HomeSecurityMicrosoft Help Index Files Abused to Execute PipeMagic Malware

Abuse of Microsoft Help Index Files to execute PipeMagic malware

Researchers have discovered a sophisticated campaign that exploits Microsoft Help Index Files (.mshi) to distribute the infamous PipeMagic malware backdoor.

Microsoft Help Index Files PipeMagic malware

The campaign, which has targeted organizations in Saudi Arabia and Brazil throughout 2025, demonstrates the continued improvement of the infection methods and persistence mechanisms used by attackers.

PipeMagic first appeared in December 2022 during a ransomware campaign by the RansomExx group industrialtargeting companies in Southeast Asia. However, the malware became widely known when it began exploiting CVE-2025-29824, a vulnerability that Microsoft said was actively being exploited during the April 2025 update cycle.

See also: Hackers target Russian companies with EAGLET backdoor

The backdoor operators have shown remarkable adaptability. They started exploiting the CVE-2017-0144 and have now reached more sophisticated social engineering techniques. The latest version of the PipeMagic malware has expanded its geographical reach, with researchers at Securelist detecting infections in multiple regions.

Misuse of Microsoft Help Index Files

The malware maintains its core functionality as a flexible backdoor, with two distinct modes: operating as a full-fledged remote access tool and as a network gateway for lateral movement into the compromised infrastructure. What sets the 2025 campaign apart is its innovative use of Microsoft Help Index Files as the initial means of infection.

Microsoft Help Index Files PipeMagic malware

These files, which typically contain metadata for Microsoft help documentation, have been weaponized to carry obfuscated C# code along with encrypted payloads. The malicious .mshi files leverage the legitimate MSBuild framework for execution, effectively bypassing traditional security checks.

The infection chain begins when victims execute the malicious metafile.mshi file, which contains obfuscated C# code combined with an extensive hexadecimal string. Execution is accomplished via a carefully crafted command line sequence. The embedded C# code performs two functions. First, it decrypts the accompanying shellcode using the RC4 stream cipher with a hardcoded 64-character hexadecimal key (4829468622e6b82ff056e3c945dd99c94a1f0264d980774828aadda326b775e5).

See also: Elastic EDR: Zero-day allows malware execution & BSOD

After successful decryption, the code executes the shellcode via the Windows API function EnumDeviceMonitor. A technique is used that inserts the shellcode pointer into the third parameter of the function, while setting the first two parameters to zero. The decrypted shellcode contains executable code specifically designed for Windows 32-bit systems. It also uses sophisticated evasion techniques, making static analysis significantly more difficult.

The shellcode eventually loads an unencrypted executable, embedded within its own structure, establishing the presence of the PipeMagic malware backdoor on the compromised system and allowing communication via the typical infrastructure at 127.0.0.1:8082.

What does this mean for businesses and SOC teams?

The 2025 PipeMagic campaign demonstrates that attackers:

  • They are constantly improving old techniques with new approaches.
  • They utilize “legitimate” tools (MSBuild, Windows APIs) to avoid detection.
  • They target different locations (S. Arabia, Brazil) with customized campaigns.
Abuse of Microsoft Help Index Files to execute PipeMagic malware

Backdoor protection 

Organizations can protect their networks from backdoors by implementing various security. First, it is important to keep their systems up to date. This means they should regularly install the latest updates and security patches on all operating systems and applications.

Additionally, organizations should use security solutions that include intrusion detection and malware protection. These solutions can help detect and prevent attacks.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: Linux malware leak (linked to North Korean hackers)

Staff training is also critical to avoiding backdoors. Employees need to be aware of the risks associated with cybersecurity  and the tactics used by attackers, such as phishing .

Finally, the principle of least access should be applied . This means that users and devices should only have the necessary access permissions they need to perform their tasks.

Source: cybersecuritynews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS