EXECUTIVE SUMMARY:
Storm-2603 is a threat actor responsible for a series of ransomware operations that preceded its well-known exploitation campaign known as ToolShell. The group leveraged four SharePoint vulnerabilities—CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771—to gain initial access to targeted environments. Following exploitation, Storm-2603 deployed malware loaders and command-and-control implants that paved the way for ransomware delivery. These early activities involved domain infrastructure reuse, malware-laced installers, and the blending of legitimate-looking tools with malicious payloads. The attacker’s objective was to quietly compromise systems using stealthy methods before delivering ransomware, indicating a structured and staged approach to intrusion.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
Storm-2603 is a threat actor responsible for a series of ransomware operations that preceded its well-known exploitation campaign known as ToolShell. The group leveraged four SharePoint vulnerabilities—CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771—to gain initial access to targeted environments. Following exploitation, Storm-2603 deployed malware loaders and command-and-control implants that paved the way for ransomware delivery. These early activities involved domain infrastructure reuse, malware-laced installers, and the blending of legitimate-looking tools with malicious payloads. The attacker’s objective was to quietly compromise systems using stealthy methods before delivering ransomware, indicating a structured and staged approach to intrusion.[emaillocker id="1283"]
The group operates a custom command-and-control framework called ak47c2, which includes both HTTP and DNS-based variants. In multiple incidents, they delivered payloads through archives containing DNS tunneling backdoors, sideloaded DLLs, and MSI installers. One such attack leveraged a fake installer to execute a DNS backdoor that communicated with attacker-controlled infrastructure. Alongside this, DLL sideloading techniques were used to activate ransomware like LockBit Black and Warlock. The group also used vulnerable drivers to disable endpoint protections, helping ensure the ransomware payloads could execute without interference. These techniques were layered to maximize stealth and persistence, allowing attackers to operate within compromised systems with minimal detection.
Storm-2603’s operations highlight the growing trend of attackers combining vulnerability exploitation with file-based malware delivery. Its tactics—such as DNS tunneling, DLL hijacking, and infrastructure impersonation—make traditional defenses less effective. By embedding malicious logic in trusted software components and using known file formats, the group makes detection and attribution more difficult. Security teams should be alert to signs of sideloaded DLL activity, abnormal DNS patterns, and executions involving unsigned MSI files. Defending against threats like Storm-2603 requires deeper behavioral monitoring and proactive detection of lateral movement and post-exploitation activity.
THREAT PROFILE:
| Tactic | Technique ID | Technique | Sub-Technique |
| Initial Access | T1190 | Exploit Public-Facing Application | - |
| Execution | T1059.001 | Command and Scripting Interpreter | PowerShell |
| Persistence | T1547.001 | Boot or Logon Autostart Execution | Registry Run Keys / Startup Folder |
| Privilege Escalation | T1068 | Exploitation for Privilege Escalation | – |
| Defense Evasion | T1218.011 | System Binary Proxy Execution | Rundll32 |
| T1218.005 | Mshta | ||
| T1562.001 | Impair Defenses | Disable or Modify Tools | |
| Lateral Movement | T1021.001 | Remote Services | Remote Desktop Protocol |
| Command & Control | T1071.001 | Application Layer Protocol | Web Protocols |
| T1071.004 | DNS | ||
| Impact | T1486 | Data Encrypted for Impact | – |
REFERENCES:
The following reports contain further technical details:
[/emaillocker]