Storm-2603 is a threat actor associated with the deployment of Warlock ransomware and tracked under aliases including GOLD SALEM, CL-CRI-1040, and Warlock Group. The actor has been active since at least March 2025, with sustained targeting of vulnerable internet-facing and on-premises enterprise applications, especially Microsoft SharePoint Server. Multiple reports describe Storm-2603 exploiting SharePoint vulnerabilities from mid-2025 onward, including the ToolShell exploit chain, to gain initial access, deploy web shells, steal SharePoint cryptographic material, and establish persistence. The group has also been linked to exploitation of other enterprise software vulnerabilities, including flaws affecting SmarterMail, SolarWinds Web Help Desk, and Gladinet CentreStack, in operations that led to ransomware deployment or extortion activity. Storm-2603’s tradecraft blends vulnerability exploitation with extensive post-compromise abuse of legitimate administrative and remote access tooling. Observed activity includes command execution through IIS worker processes, deployment of web shells, creation of new local and domain administrator accounts, credential theft from LSASS using Mimikatz, lateral movement with PsExec, Impacket, WMI, and WinRM, and ransomware distribution through Group Policy Objects. The actor has repeatedly used legitimate tools and services such as Velociraptor, Cloudflare Tunnels, Zoho Assist, and SSH via Visual Studio Code to maintain redundant access while blending into normal administrative activity. Defense evasion has included disabling security products through registry modification, DLL side-loading, custom backdoors, scheduled tasks, IIS component manipulation, and Bring Your Own Vulnerable Driver techniques using vulnerable kernel drivers to tamper with memory and suppress endpoint protections. Victimology spans commercial enterprises, government entities, and large multinational organizations across North America, Europe, and South America, with additional reporting tying the actor to attacks affecting sectors such as telecommunications, healthcare, finance, education, and critical infrastructure. Public leak-site activity attributed to the Warlock/GOLD SALEM operation indicates a broad extortion model involving data theft, victim shaming, and claimed data sales. The group has publicly listed dozens of victims since 2025 and appears to operate opportunistically against exposed enterprise infrastructure rather than focusing exclusively on a single vertical. Microsoft has assessed Storm-2603 with moderate confidence as a likely China-based threat actor, and some reporting characterizes it as China-based. However, this attribution is not uniformly corroborated across the industry, and at least some researchers have stated that available evidence is insufficient to independently confirm the China nexus. What is well supported is that Storm-2603 is a ransomware and extortion actor with a demonstrated pattern of rapidly operationalizing newly disclosed vulnerabilities in externally exposed enterprise software, particularly on-premises SharePoint, and combining that access with credential theft, stealthy persistence, lateral movement, and ransomware deployment.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
41 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
21 malware families attributed to this actor across reporting.
16 additional families tracked in Mallory.
12 CVEs this actor has used in observed campaigns. 12 of them exploited in the wild.
On July 19, 2025, security researchers and enterprise defenders began tracking a large-scale exploitation campaign targeting on-premises Microsoft SharePoint Servers (CVE-2025-53770). On July 19th, Microsoft confirmed that a zero day vulnerability impacting on-premises Microsoft SharePoint Servers, dubbed “ToolShell”. CVE-2025-53770 has been added to CISA’s Known Exploited Vulnerabilities (KEV) catalog on July 20, 2025.
Researchers also identified Linen Typhoon, Violet Typhoon, and Storm-2603 had in fact started using the two flaws (CVE-2025-49706 and CVE-2025-49704) as zero-days, based on its investigation into ongoing attacks on SharePoint Servers. CVE-2025-49704 : Type: Unauthenticated File Upload Allows arbitrary .aspx files (webshells) to be written to accessible paths.
Researchers also identified Linen Typhoon, Violet Typhoon, and Storm-2603 had in fact started using the two flaws (CVE-2025-49706 and CVE-2025-49704) as zero-days, based on its investigation into ongoing attacks on SharePoint Servers. CVE-2025-49706 : Type: XAML Deserialization Enables post-auth remote code execution (RCE).
CVE-2025-53771 : Type: Input Validation / Path Traversal Used to overwrite or plant files in sensitive directories, aiding persistence.
SmarterMail CVE-2026-23760 Storm-2603 (Warlock) ... observed during intrusions that lead to WarLock ransomware deployment or data exfiltration
7 more CVEs tied to this actor tracked in Mallory.
197 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Exploiting on-premises SharePoint vulnerabilities to gain initial access and deploy Warlock ransomware; documented activity includes creating local and domain admin accounts, deploying Cloudflare tunneling, Zoho Assist, and SSH via Visual Studio Code, and disabling endpoint protection with the vulnerable driver NSecKrnl.sys.
Known for deploying Warlock ransomware via exploitation of on-premises SharePoint vulnerabilities; mentioned here as background on broader SharePoint exploitation activity, not as the attributed actor behind the HSIN intrusion.
Ransomware activity involving exploitation of known vulnerabilities in on-premises SharePoint servers, deployment of Warlock ransomware, persistence establishment, lateral movement across organizations, privilege escalation, and use of multiple remote access channels.
Linked to exploitation campaigns targeting vulnerable Microsoft SharePoint Server instances for initial access, followed by persistence, lateral movement, privilege escalation, and potential ransomware deployment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.