Close Menu

    Subscribe to Updates

    Get the latest tech news from Tallwire.

      What's Hot

      Silicon Against Suffering

      June 6, 2026

      Small Websites Fight Back Against Google’s AI Takeover

      June 6, 2026

      AI Race-Bait Marketing Scams Exploit Empathy to Sell Cheap Imports

      June 6, 2026
      Facebook X (Twitter) Instagram
      • Tech
      • AI
      • Get In Touch
      Facebook X (Twitter) LinkedIn
      TallwireTallwire
      • Tech

        Anthropic’s Massive Funding Surge Signals the Next Phase of the AI Power Struggle

        June 5, 2026

        AI Startup Trades Free Housecleaning for Robot Training Data

        June 5, 2026

        Microsoft AI Chief Warns Open-Source Shortcuts Could Deepen the AI Power Divide

        June 5, 2026

        SpaceX’s Texas IPO Move Signals Rising Financial Power Shift Toward the Lone Star State

        June 4, 2026

        Silicon Valley’s Luster Fades for India’s Tech Elite

        June 4, 2026
      • AI

        Anthropic’s Massive Funding Surge Signals the Next Phase of the AI Power Struggle

        June 5, 2026

        AI Gold Rush Floods New York’s Subways as Tech Firms Chase Wall Street Attention

        June 5, 2026

        AI Accessibility Breakthrough Shows Technology’s Best Use Case

        June 5, 2026

        AI Startup Trades Free Housecleaning for Robot Training Data

        June 5, 2026

        Illinois Moves Toward Aggressive AI Oversight With Mandatory Independent Audits

        June 5, 2026
      • Security

        AI Race-Bait Marketing Scams Exploit Empathy to Sell Cheap Imports

        June 6, 2026

        Microsoft’s Threat Against Security Researcher Sparks Backlash Across Cybersecurity Community

        June 5, 2026

        Australian Welfare Agency Hit by Wave of Identity Theft Attacks

        June 3, 2026

        Pentagon Warning Exposes How Big Tech Data Trails Are Putting American Troops in the Crosshairs

        June 3, 2026

        Americans’ Personal Data Emerges as the New Digital Gold Rush

        June 2, 2026
      • Health

        Drug-Resistant Typhoid Raises New Fears of a Global Health Crisis

        June 6, 2026

        AI Accessibility Breakthrough Shows Technology’s Best Use Case

        June 5, 2026

        Smart Tattoo Breakthrough Could Revolutionize Early Skin Cancer Detection

        June 4, 2026

        California Moves Closer to Social Media Ban for Children Under 16

        June 3, 2026

        Wearable Pregnancy Patch Signals A Major Leap Forward In Protecting High-Risk Mothers

        June 1, 2026
      • Science

        Drug-Resistant Typhoid Raises New Fears of a Global Health Crisis

        June 6, 2026

        AI Accessibility Breakthrough Shows Technology’s Best Use Case

        June 5, 2026

        Smart Tattoo Breakthrough Could Revolutionize Early Skin Cancer Detection

        June 4, 2026

        Blue Origin Rocket Explosion Deals Major Blow to Bezos Space Ambitions

        June 3, 2026

        Space Race For AI Infrastructure Moves Beyond Earth

        June 2, 2026
      • Tech

        Zuckerberg’s Superyacht Arrival Sparks Backlash Amid Meta Layoffs

        June 1, 2026

        Nvidia Chief Deepens China Ties Amid Intensifying AI Power Struggle

        June 1, 2026

        Pope Leo XIV Challenges Silicon Valley’s Vision for Artificial Intelligence

        May 31, 2026

        Peter Thiel’s Argentina Bet Signals Growing Global Confidence in Milei’s Economic Experiment

        May 31, 2026

        Tech Billionaire Steps Into San Francisco Tax Revolt

        May 28, 2026
      TallwireTallwire
      Home»Tech»Microsoft Flags Sophisticated PipeMagic Malware Masquerading as ChatGPT Desktop
      Tech

      Microsoft Flags Sophisticated PipeMagic Malware Masquerading as ChatGPT Desktop

      Updated:February 21, 20262 Mins Read
      Facebook Twitter Pinterest LinkedIn Tumblr Email
      Microsoft Flags Sophisticated PipeMagic Malware Masquerading as ChatGPT Desktop
      Microsoft Flags Sophisticated PipeMagic Malware Masquerading as ChatGPT Desktop
      Share
      Facebook Twitter LinkedIn Pinterest Email

      Microsoft has raised the alarm over a new strain of modular malware known as PipeMagic, which is being disguised as a ChatGPT desktop application to sneak into systems via GitHub; exploiting a zero-day elevation-of-privilege vulnerability in Windows Common Log File System (CVE-2025-29824), PipeMagic serves as a stealthy backdoor and infostealer with dynamic payload execution, encrypted inter-process communication, and self-updating capabilities, affecting select victims across IT, financial and real-estate sectors in the US, Europe, South America, and the Middle East.

      Sources: DarkReading, Hacker News, TechRadarPro

      Key Takeaways

      – Modular and Stealthy: PipeMagic delivers payloads in memory, communicates via encrypted named pipes, and supports modules loaded from command-and-control servers.

      – Zero-Day Exploit at Play: The malware leverages CVE-2025-29824—a critical Windows CLFS flaw patched by Microsoft in April—but many systems remain vulnerable.

      – Geopolitical and Sector Spread: Though seemingly limited in scope for now, victims span multiple continents and sectors including IT, real-estate, finance, and more.

      In-Depth Article

      Microsoft is sounding the alarm on PipeMagic, an advanced malware framework camouflaged as a familiar open-source ChatGPT desktop app. Attackers have hijacked a legitimate GitHub project—slipped in malicious code—and packaged it into an in-memory dropper. Once executed, the dropper decrypts and launches the embedded malware directly into system memory, leaving little trace on disk.

      What really sets PipeMagic apart is its modular architecture. It can dynamically load payloads via encrypted named pipes, maintain communication with command-and-control servers, escalate its privileges, and even update itself—all without touching a file on disk. The entire operation revolves around exploiting CVE-2025-29824, a critical Windows vulnerability in the Common Log File System that Microsoft patched earlier this year. Unfortunately, unpatched systems remain exposed, and PipeMagic has shown capability in executing ransomware and backdoor infections across IT, finance, and real-estate targets in regions spanning the US, Europe, South America, and the Middle East.

      Security firms like Kaspersky and BI.ZONE have confirmed that PipeMagic has resurfaced in “Play” ransomware campaigns, reaffirming its evolving threat. The risk? Even a trusted open-source appearance can be lethal. Organizations should treat every third-party app with suspicion, patch promptly, and ensure their detection tools are configured to catch this kind of in-memory modular malware. Vigilance remains the best defense.

      Microsoft Ransomware
      Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
      Previous ArticleMicrosoft Edge Web Browser releases Co-Pilot Mode
      Next Article Microsoft Launches Its First Homegrown AI Image Generator, Signaling a Break From OpenAI Dependence

      Related Posts

      Anthropic’s Massive Funding Surge Signals the Next Phase of the AI Power Struggle

      June 5, 2026

      Microsoft’s Threat Against Security Researcher Sparks Backlash Across Cybersecurity Community

      June 5, 2026

      AI Startup Trades Free Housecleaning for Robot Training Data

      June 5, 2026

      Microsoft AI Chief Warns Open-Source Shortcuts Could Deepen the AI Power Divide

      June 5, 2026
      Add A Comment
      Leave A Reply Cancel Reply

      Editors Picks

      Anthropic’s Massive Funding Surge Signals the Next Phase of the AI Power Struggle

      June 5, 2026

      AI Startup Trades Free Housecleaning for Robot Training Data

      June 5, 2026

      Microsoft AI Chief Warns Open-Source Shortcuts Could Deepen the AI Power Divide

      June 5, 2026

      SpaceX’s Texas IPO Move Signals Rising Financial Power Shift Toward the Lone Star State

      June 4, 2026
      Popular Topics
      Startup Viral Space trending Satellite spotlight Taiwan Tech starlink Tesla Cybertruck UAE Tech Series B Software SpaceX Satya Nadella Tim Cook Tesla Stocks Samsung Series A Sundar Pichai
      Major Tech Companies
      • Apple News
      • Google News
      • Meta News
      • Microsoft News
      • Amazon News
      • Samsung News
      • Nvidia News
      • OpenAI News
      • Tesla News
      • AMD News
      • Anthropic News
      • Elbit News
      AI & Emerging Tech
      • AI Regulation News
      • AI Safety News
      • AI Adoption
      • Quantum Computing News
      • Robotics News
      Key People
      • Sam Altman News
      • Jensen Huang News
      • Elon Musk News
      • Mark Zuckerberg News
      • Sundar Pichai News
      • Tim Cook News
      • Satya Nadella News
      • Mustafa Suleyman News
      Global Tech & Policy
      • Israel Tech News
      • India Tech News
      • Taiwan Tech News
      • UAE Tech News
      Startups & Emerging Tech
      • Series A News
      • Series B News
      • Startup News
      Tallwire
      Facebook X (Twitter) LinkedIn Threads Instagram RSS
      • Tech
      • Entertainment
      • Business
      • Government
      • Academia
      • Transportation
      • Legal
      • Press Kit
      © 2026 Tallwire. Optimized by ARMOUR Digital Marketing Agency.

      Type above and press Enter to search. Press Esc to cancel.