Storm-2603 is a ransomware and intrusion cluster associated with the Warlock ransomware operation and tracked by other vendors as GOLD SALEM, CL-CRI-1040, and Warlock Group. Microsoft has assessed the actor with moderate confidence as China-based, although some researchers have stated they lack sufficient evidence to independently confirm that attribution. The group has been active since at least March 2025 and became especially notable for exploiting vulnerabilities in on-premises Microsoft SharePoint Server from mid-2025 onward, including the ToolShell exploit chain, to gain initial access and deploy ransomware. Reporting also links the actor to exploitation of additional enterprise software vulnerabilities, including flaws in Gladinet CentreStack, SolarWinds Web Help Desk, and SmarterMail. Storm-2603 primarily targets internet-facing enterprise infrastructure and has victimized organizations across North America, Europe, and South America, including government entities, commercial organizations, healthcare, finance, education, telecommunications, and critical infrastructure. Public reporting also ties the actor to attacks affecting U.S.-based organizations and public-sector environments. The group has operated a leak site and used extortion tactics alongside ransomware deployment. Observed tradecraft includes exploitation of public-facing applications for initial access; deployment of web shells on SharePoint; abuse of legitimate remote administration and DFIR tools such as Velociraptor, Cloudflare Tunnel, Zoho Assist, and Visual Studio Code SSH tunnels for persistence and post-exploitation; creation of new local and domain administrator accounts; credential theft from LSASS using Mimikatz; lateral movement with PsExec, Impacket, WinRM, and WMI; and ransomware deployment via Group Policy Objects. Defense evasion has included disabling security products through registry changes, use of Bring Your Own Vulnerable Driver techniques with vulnerable kernel drivers, DLL sideloading, and custom backdoors. The actor has also been observed conducting reconnaissance and data theft during intrusions, and some reporting links it to both Warlock and LockBit ransomware deployment. Overlapping multi-actor intrusions have complicated attribution in some cases, but Storm-2603 is consistently associated with SharePoint exploitation leading to Warlock ransomware and extortion activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
41 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
21 malware families attributed to this actor across reporting.
16 additional families tracked in Mallory.
12 CVEs this actor has used in observed campaigns. 12 of them exploited in the wild.
On July 19, 2025, security researchers and enterprise defenders began tracking a large-scale exploitation campaign targeting on-premises Microsoft SharePoint Servers (CVE-2025-53770). On July 19th, Microsoft confirmed that a zero day vulnerability impacting on-premises Microsoft SharePoint Servers, dubbed “ToolShell”. CVE-2025-53770 has been added to CISA’s Known Exploited Vulnerabilities (KEV) catalog on July 20, 2025.
Researchers also identified Linen Typhoon, Violet Typhoon, and Storm-2603 had in fact started using the two flaws (CVE-2025-49706 and CVE-2025-49704) as zero-days, based on its investigation into ongoing attacks on SharePoint Servers. CVE-2025-49704 : Type: Unauthenticated File Upload Allows arbitrary .aspx files (webshells) to be written to accessible paths.
Researchers also identified Linen Typhoon, Violet Typhoon, and Storm-2603 had in fact started using the two flaws (CVE-2025-49706 and CVE-2025-49704) as zero-days, based on its investigation into ongoing attacks on SharePoint Servers. CVE-2025-49706 : Type: XAML Deserialization Enables post-auth remote code execution (RCE).
CVE-2025-53771 : Type: Input Validation / Path Traversal Used to overwrite or plant files in sensitive directories, aiding persistence.
SmarterMail CVE-2026-23760 Storm-2603 (Warlock) ... observed during intrusions that lead to WarLock ransomware deployment or data exfiltration
7 more CVEs tied to this actor tracked in Mallory.
197 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Exploiting on-premises SharePoint vulnerabilities to gain initial access and deploy Warlock ransomware; documented activity includes creating local and domain admin accounts, deploying Cloudflare tunneling, Zoho Assist, and SSH via Visual Studio Code, and disabling endpoint protection with the vulnerable driver NSecKrnl.sys.
Known for deploying Warlock ransomware via exploitation of on-premises SharePoint vulnerabilities; mentioned here as background on broader SharePoint exploitation activity, not as the attributed actor behind the HSIN intrusion.
Ransomware activity involving exploitation of known vulnerabilities in on-premises SharePoint servers, deployment of Warlock ransomware, persistence establishment, lateral movement across organizations, privilege escalation, and use of multiple remote access channels.
Linked to exploitation campaigns targeting vulnerable Microsoft SharePoint Server instances for initial access, followed by persistence, lateral movement, privilege escalation, and potential ransomware deployment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.