AK47C2 is a modular, multi-protocol backdoor within the Project AK47 toolkit associated with the financially motivated Storm-2603 activity cluster, also tracked as CL-CRI-1040. Active since at least March 2025, the toolkit has been used in intrusions involving exploitation of Microsoft SharePoint ToolShell vulnerabilities, including CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771. AK47C2 has DNS-tunneling and HTTP-based variants that communicate with command-and-control infrastructure, accept arbitrary commands, and support configurable sleep intervals. Its DNS variant encodes tasking and command output for transport in DNS queries and responses, while the HTTP variant communicates through HTTP POST requests. AK47C2 has been deployed alongside DLL-side-loading loaders and ransomware payloads, including AK47/X2ANYLOCK, in enterprise-targeted ransomware operations. Storm-2603 has been assessed as financially motivated; available reporting does not establish a conclusive nation-state attribution for the cluster.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Storm-2603 and CL-CRI-1040 ... exploit internet-facing on-premise SharePoint Servers (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771). | The primary backdoor, AK47C2 supports both DNS and HTTP protocols for command-and-control communications, encrypts data, terminates processes, and demands ransom.
This group has been exploiting recently disclosed SharePoint vulnerabilities, collectively referred as “ToolShell” (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771) to deploy a specialised malware toolkit named Project AK47. | The primary backdoor, AK47C2 supports both DNS and HTTP protocols for command-and-control communications, encrypts data, terminates processes, and demands ransom.
Storm-2603 and CL-CRI-1040 ... exploit internet-facing on-premise SharePoint Servers (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771). | The primary backdoor, AK47C2 supports both DNS and HTTP protocols for command-and-control communications, encrypts data, terminates processes, and demands ransom.
This group has been exploiting recently disclosed SharePoint vulnerabilities, collectively referred as “ToolShell” (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771) to deploy a specialised malware toolkit named Project AK47. | The primary backdoor, AK47C2 supports both DNS and HTTP protocols for command-and-control communications, encrypts data, terminates processes, and demands ransom.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The primary backdoor, AK47C2 supports both DNS and HTTP protocols for command-and-control communications, encrypts data, terminates processes, and demands ransom.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom C2 framework used by Storm-2603, supporting HTTP and DNS tunneling for command and control communications.
Custom command-and-control framework used by Storm-2603/CL-CRI-1040 in intrusions associated with Warlock/Anylock ransomware deployment; part of a broader toolkit including backdoors and loaders delivered via DLL sideloading.
Custom multi-protocol backdoor used by CL-CRI-1040/Storm-2603. Implements DNS- and HTTP-based C2 (dnsclient/httpclient), uses XOR-encoding and hex-encoding of messages, supports setting sleep duration (in later variants) and arbitrary command execution, and returns execution output to C2.
Project AK47's primary modular backdoor. It communicates with C2 infrastructure over DNS and HTTP, can encrypt data, terminate processes, and issue ransom demands.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.