AK47 C2 is a bespoke command-and-control framework used by the China-nexus cluster Storm-2603 in campaigns exploiting Microsoft SharePoint vulnerabilities during the first half of 2025. The framework is also referred to as ak47c2 and comprises two custom backdoors: AK47HTTP and AK47DNS. Both implants hide their windows, collect hostnames, execute commands via cmd.exe, and return command output to attacker-controlled infrastructure. AK47HTTP communicates over plain HTTP POST requests and sends XOR-encrypted JSON blobs. AK47DNS communicates through DNS queries to a fake C2 domain, update.micfosoft[.]com, and encodes data using XOR and hexadecimal encoding. Reporting linked Storm-2603’s use of AK47 C2 to targeting of organizations in Latin America and APAC. The broader intrusion set also involved open-source tools, DLL sideloading through legitimate applications such as 7-Zip and clink.exe, and ransomware deployment including LockBit Black and a Warlock-linked .x2anylock variant. Microsoft linked Storm-2603 C2 infrastructure to a SharePoint web shell, and Check Point reported overlap between this tooling and earlier ransomware attacks dating back to at least March 2025.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Storm-2603 uses the AK47 C2 framework with two custom backdoors, respectively named AK47DNS and AK47HTTP. AK47DNS uses DNS queries to communicate with a fake C2 domain (update.micfosoft[.]com), encoding data via XOR and hex. AK47HTTP uses plain HTTP POSTs, sending XOR-encrypted JSON blobs.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
"Threat actors have been observed actively exploiting a seven-year-old security flaw in Cisco IOS and Cisco IOS XE software as a means to establish persistent access to target networks." / "Threat actors are exploiting a nearly two-year-old security flaw in Apache ActiveMQ to gain persistent access to cloud Linux systems" / "The exploit ... chains together CVE-2025-31324 and CVE-2025-42999 to bypass authentication and achieve remote code execution"
Storm-2603 uses the AK47 C2 framework with two custom backdoors, respectively named AK47DNS and AK47HTTP.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Bespoke C2 framework with HTTP- and DNS-based clients used in intrusions associated with ransomware activity (Warlock/LockBit mentioned).
Custom command-and-control framework used by Storm-2603 with DNS- and HTTP-based implants that hide windows, collect hostnames, execute commands via cmd.exe, and return results to attacker-controlled infrastructure.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.