


Perceptive Security
SOC/SIEM Consultancy

Storm-0249 Escalates Ransomware Attacks with ClickFix, Fileless PowerShell, and DLL Sideloading
Published:
9 December 2025 at 13:37:00
Alert date:
9 December 2025 at 15:00:46
Source:
thehackernews.com
Storm-0249 threat actor is evolving from an initial access broker to conducting advanced ransomware attacks. The group is now using sophisticated techniques including domain spoofing, DLL side-loading, and fileless PowerShell execution. These methods enable them to bypass security defenses, infiltrate networks, maintain persistence, and operate undetected. The evolution represents a significant escalation in the threat actor's capabilities and poses serious concerns for organizations. The shift to more advanced tactics indicates increased sophistication in their attack methodology.
Technical details
Mitigation steps:
Affected products:
Related links:
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
