Threat Advisory

Storm-2603 APT Exploits SmarterMail to Deploy Warlock Ransomware with High-Privilege Execution

Threat: Ransomware
Threat Actor Name: Storm-2603
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

A threat actor, tracked as Storm-2603, has been observed actively exploiting critical vulnerabilities in SmarterTools SmarterMail email server software, CVE-2026-23760 and CVE-2026-24423, to gain unauthorized access to internet-facing systems and set up conditions for a Warlock ransomware operation. The exploitation centers on bypassing authentication and chaining built-in administrative capabilities to achieve deeper control over targeted infrastructure, illustrating how threat actors are rapidly weaponizing newly disclosed vulnerabilities to stage ransomware activities.[/subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

A threat actor, tracked as Storm-2603, has been observed actively exploiting critical vulnerabilities in SmarterTools SmarterMail email server software, CVE-2026-23760 and CVE-2026-24423, to gain unauthorized access to internet-facing systems and set up conditions for a Warlock ransomware operation. The exploitation centers on bypassing authentication and chaining built-in administrative capabilities to achieve deeper control over targeted infrastructure, illustrating how threat actors are rapidly weaponizing newly disclosed vulnerabilities to stage ransomware activities.[emaillocker id="1283"]

The initial access vector stems from a flaw in the SmarterMail password reset API that fails to properly validate inputs, allowing attackers to overwrite administrator credentials without valid authentication. While this alone does not grant system-level execution, Storm-2603 couples the authentication bypass with abuse of the servers Volume Mount administrative feature to inject arbitrary commands and attain full control of the underlying operating system. With that foothold, the adversary leverages Windows Installer mechanisms to download and install a malicious MSI payload from a cloud backend platform, deploying Velociraptor, a legitimate digital forensics and incident response tool, for command-and-control and persistent access. Observed activity did not show ransomware deployment at the time of detection, but tradecraft aligned with prior Warlock ransomware staging phases indicates the goal of preparing the environment for subsequent extortion activity.

It underscores the growing of ransomware actors in blending exploitation of known security bugs with the misuse of legitimate administrative features and tooling to reduce detectability and strengthen persistence. It highlights that simply patching one vulnerability may not be sufficient when attackers can chain multiple techniques to achieve full system control. Organizations operating internet-facing mail and collaboration services should prioritize immediate remediation of the identified flaws, isolate critical infrastructure from broader internal networks, and enhance monitoring for anomalous use of legitimate tools such as remote command execution and unauthorized installer downloads. Failure to address these vectors can leave systems exposed to advanced ransomware staging operations and potential data loss or service disruption.

 

THREAT PROFILE:

Tactic Technique Id Technique Sub-technique
Execution T1059.003 Command and Scripting Interpreter Windows Command Shell
Persistence T1543.003 Create or Modify System Process Windows Service
Defense Evasion T1562.001 Impair Defenses Disable or Modify Tools
Credential Access T1555.003 Credentials from Password Stores Credentials from Web Browsers
Discovery T1083 File and Directory Discovery -
Lateral Movement T1021.002 Remote Services SMB/Windows Admin Shares
Command and Control T1071.001 Application Layer Protocol Web Protocols
Impact T1486 Data Encrypted for Impact -

 

REFERENCES:

The following reports contain further technical details:

https://securityonline.info/email-under-siege-storm-2603-exploits-smartermail-to-deploy-warlock-ransomware/

https://reliaquest.com/blog/threat-spotlight-storm-2603-exploits-CVE-2026-23760-to-stage-warlock-ransomware

[/emaillocker]
crossmenu