Researchers have discovered a sophisticated campaign that exploits Microsoft Help Index Files (.mshi) to distribute the infamous PipeMagic malware backdoor.

The campaign, which has targeted organizations in Saudi Arabia and Brazil throughout 2025, demonstrates the continued improvement of the infection methods and persistence mechanisms used by attackers.
PipeMagic first appeared in December 2022 during a ransomware campaign by the RansomExx group industrialtargeting companies in Southeast Asia. However, the malware became widely known when it began exploiting CVE-2025-29824, a vulnerability that Microsoft said was actively being exploited during the April 2025 update cycle.
See also: Hackers target Russian companies with EAGLET backdoor
The backdoor operators have shown remarkable adaptability. They started exploiting the CVE-2017-0144 and have now reached more sophisticated social engineering techniques. The latest version of the PipeMagic malware has expanded its geographical reach, with researchers at Securelist detecting infections in multiple regions.
Misuse of Microsoft Help Index Files
The malware maintains its core functionality as a flexible backdoor, with two distinct modes: operating as a full-fledged remote access tool and as a network gateway for lateral movement into the compromised infrastructure. What sets the 2025 campaign apart is its innovative use of Microsoft Help Index Files as the initial means of infection.

These files, which typically contain metadata for Microsoft help documentation, have been weaponized to carry obfuscated C# code along with encrypted payloads. The malicious .mshi files leverage the legitimate MSBuild framework for execution, effectively bypassing traditional security checks.
The infection chain begins when victims execute the malicious metafile.mshi file, which contains obfuscated C# code combined with an extensive hexadecimal string. Execution is accomplished via a carefully crafted command line sequence. The embedded C# code performs two functions. First, it decrypts the accompanying shellcode using the RC4 stream cipher with a hardcoded 64-character hexadecimal key (4829468622e6b82ff056e3c945dd99c94a1f0264d980774828aadda326b775e5).
See also: Elastic EDR: Zero-day allows malware execution & BSOD
After successful decryption, the code executes the shellcode via the Windows API function EnumDeviceMonitor. A technique is used that inserts the shellcode pointer into the third parameter of the function, while setting the first two parameters to zero. The decrypted shellcode contains executable code specifically designed for Windows 32-bit systems. It also uses sophisticated evasion techniques, making static analysis significantly more difficult.
The shellcode eventually loads an unencrypted executable, embedded within its own structure, establishing the presence of the PipeMagic malware backdoor on the compromised system and allowing communication via the typical infrastructure at 127.0.0.1:8082.
What does this mean for businesses and SOC teams?
The 2025 PipeMagic campaign demonstrates that attackers:
- They are constantly improving old techniques with new approaches.
- They utilize “legitimate” tools (MSBuild, Windows APIs) to avoid detection.
- They target different locations (S. Arabia, Brazil) with customized campaigns.

Backdoor protection
Organizations can protect their networks from backdoors by implementing various security. First, it is important to keep their systems up to date. This means they should regularly install the latest updates and security patches on all operating systems and applications.
Additionally, organizations should use security solutions that include intrusion detection and malware protection. These solutions can help detect and prevent attacks.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: Linux malware leak (linked to North Korean hackers)
Staff training is also critical to avoiding backdoors. Employees need to be aware of the risks associated with cybersecurity and the tactics used by attackers, such as phishing .
Finally, the principle of least access should be applied . This means that users and devices should only have the necessary access permissions they need to perform their tasks.
Source: cybersecuritynews.com
