Threat Advisory

Ransomware Campaign by Storm 2603 Exploiting SharePoint Vulnerabilities

Threat: Vulnerability/Ransomware
Threat Actor Name: Storm-2603
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Storm-2603 is a threat actor responsible for a series of ransomware operations that preceded its well-known exploitation campaign known as ToolShell. The group leveraged four SharePoint vulnerabilities—CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771—to gain initial access to targeted environments. Following exploitation, Storm-2603 deployed malware loaders and command-and-control implants that paved the way for ransomware delivery. These early activities involved domain infrastructure reuse, malware-laced installers, and the blending of legitimate-looking tools with malicious payloads. The attacker’s objective was to quietly compromise systems using stealthy methods before delivering ransomware, indicating a structured and staged approach to intrusion.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Storm-2603 is a threat actor responsible for a series of ransomware operations that preceded its well-known exploitation campaign known as ToolShell. The group leveraged four SharePoint vulnerabilities—CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771—to gain initial access to targeted environments. Following exploitation, Storm-2603 deployed malware loaders and command-and-control implants that paved the way for ransomware delivery. These early activities involved domain infrastructure reuse, malware-laced installers, and the blending of legitimate-looking tools with malicious payloads. The attacker’s objective was to quietly compromise systems using stealthy methods before delivering ransomware, indicating a structured and staged approach to intrusion.[emaillocker id="1283"]

 

The group operates a custom command-and-control framework called ak47c2, which includes both HTTP and DNS-based variants. In multiple incidents, they delivered payloads through archives containing DNS tunneling backdoors, sideloaded DLLs, and MSI installers. One such attack leveraged a fake installer to execute a DNS backdoor that communicated with attacker-controlled infrastructure. Alongside this, DLL sideloading techniques were used to activate ransomware like LockBit Black and Warlock. The group also used vulnerable drivers to disable endpoint protections, helping ensure the ransomware payloads could execute without interference. These techniques were layered to maximize stealth and persistence, allowing attackers to operate within compromised systems with minimal detection.

 

Storm-2603’s operations highlight the growing trend of attackers combining vulnerability exploitation with file-based malware delivery. Its tactics—such as DNS tunneling, DLL hijacking, and infrastructure impersonation—make traditional defenses less effective. By embedding malicious logic in trusted software components and using known file formats, the group makes detection and attribution more difficult. Security teams should be alert to signs of sideloaded DLL activity, abnormal DNS patterns, and executions involving unsigned MSI files. Defending against threats like Storm-2603 requires deeper behavioral monitoring and proactive detection of lateral movement and post-exploitation activity.

 

THREAT PROFILE:

Tactic Technique ID Technique Sub-Technique
Initial Access T1190 Exploit Public-Facing Application  -
Execution T1059.001 Command and Scripting Interpreter PowerShell
Persistence T1547.001 Boot or Logon Autostart Execution Registry Run Keys / Startup Folder
Privilege Escalation T1068 Exploitation for Privilege Escalation –
Defense Evasion T1218.011 System Binary Proxy Execution Rundll32
T1218.005 Mshta
T1562.001 Impair Defenses Disable or Modify Tools
Lateral Movement T1021.001 Remote Services Remote Desktop Protocol
Command & Control T1071.001 Application Layer Protocol Web Protocols
T1071.004 DNS
Impact T1486 Data Encrypted for Impact –

 

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu