Home/Threat Actor/Storm-2603
Threat Actor

Storm-2603

storm_2603 · china · active since 2025-03

Storm-2603 (canonical Microsoft naming per July 22-23, 2025 SharePoint disclosure) is a Microsoft- tracked suspected China-based threat actor that emerged July 2025 with ToolShell SharePoint zero- day mass exploitation campaign weaponizing 4-CVE chain (CVE-2025-49704 + CVE-2025-49706 originally patched July 2025 + bypass variants CVE-2025-53770 + CVE-2025-53771 weaponized as zero-day post-patch) with unusual hybrid state-sponsored-with-cybercrime- ransomware profile.

China-based moderate-confidence attribution via Microsoft canonical disclosure ("The group that Microsoft tracks as Storm-2603 is assessed with moderate confidence to be a China- based threat actor. Microsoft has not identified links between Storm-2603 and other known Chinese threat actors. Microsoft tracks this threat actor in association with attempts to steal MachineKeys using the on-premises SharePoint vulnerabilities") + Check Point Research March 2025 prior activity retrospective ("evidence gathered following an analysis of VirusTotal artifacts shows that the group may have been active since at least March 2025, deploying ransomware families like LockBit Black and Warlock together, something that's not observed commonly among established e-crime groups") + MITRE ATT&CK Campaign C0058 + Trustwave SpiderLabs September 2025 + Fortiguard threat actor profile + Picus Security + SC Media + Help Net Security industry coverage.

standalone cluster paralleling velvet_ant + billbug + earth_alux in v0.1.154 China-aligned 2022-2025 enterprise persistence + exploitation operators cell; operational target profile 400+ organizations compromised in July 17-21, 2025 attack waves per Eye Security + high-profile victims including U.S. National Nuclear Security Administration (NNSA) + U.S. Education Department + Florida Department of Revenue + Rhode Island General Assembly per SC Media + APAC + Latin America March-July 2025 prior per Check Point VirusTotal analysis; operational attack architecture: (1) cluster- defining ToolShell SharePoint 4-CVE exploit chain with CVE-2025-49704 RCE + CVE-2025-49706 spoofing originally patched July 2025 + CVE-2025-53770 + CVE-2025-53771 bypass variants weaponized as zero- day post-patch.

(2) cluster-defining Warlock (aka X2anylock) + LockBit Black + Babuk multi- ransomware deployment with unusual operational sophistication per Check Point ("not observed commonly among established e-crime groups") + Picus Security uniform ransom notes signature ("How to decrypt my data.log" for X2anylock + LockBit README.txt naming)

(3) cluster-defining Project AK47 toolset including AK47 C2 framework + backdoor malware + supporting tools per Trustwave SpiderLabs + Fortiguard.

(4) cluster-defining DLL hijacking + DLL sideloading + BYOVD (Bring Your Own Vulnerable Driver) defense evasion tradecraft per Fortiguard.

(5) cluster-defining MachineKey theft from SharePoint servers signature objective per Microsoft enabling forged ViewState payloads + persistent authentication bypass on compromised SharePoint instances.

(6) signature DNS-controlled backdoor capability per The Hacker News August 2025.

(7) signature PsExec lateral movement living-off-the-land tradecraft per Picus Security.

(8) cluster-defining update. updatemicfosoft.com C2 domain typosquat signature per Check Point.

(9) signature parallel exploitation by Linen Typhoon (APT27) + Violet Typhoon (APT31) for espionage/IP theft + Salt Typhoon (Glowworm) deploying Zingdoor + ShadowPad + KrustyLoader against telecom + 2 African government bodies per Microsoft + Help Net Security + Symantec October 2025 establishing Storm-2603 as one of multiple Chinese clusters operationally weaponizing ToolShell SharePoint vulnerabilities.

cluster fills the March-2025- onward + ToolShell-SharePoint-zero-day-exploitation + Warlock-LockBit-Babuk-multi-ransomware-deployment + Project-AK47-toolset + China-ransomware-hybrid + MachineKeys-theft + 400+-organization-mass- compromise + U.S.-critical-infrastructure-victims position in China-aligned 2022-2025 enterprise persistence + exploitation operators cell; canonical illustration of 2025 China-aligned ransomware-hybrid actor + ToolShell SharePoint mass-exploitation + unusual multi-ransomware deployment + Project AK47 proprietary toolset + BYOVD defense evasion + MachineKeys theft + parallel-exploitation-with-Linen-Violet-Salt-Typhoon cited in essentially all subsequent 2025 SharePoint exploitation industry analyses through 2025-2026 period.

china confidence: high 14 aliases
Sigma rules200 YARA rules0 Live IOCs0 CVEs exploited4

Profile

Storm-2603 (canonical Microsoft naming per July 22-23, 2025 SharePoint disclosure) is a Microsoft- tracked suspected China-based threat actor that emerged July 2025 with ToolShell SharePoint zero- day mass exploitation campaign with unusual hybrid state-sponsored-with-cybercrime-ransomware profile. China-based attribution via Microsoft moderate- confidence assessment ("The group that Microsoft tracks as Storm-2603 is assessed with moderate confidence to be a China-based threat actor. Microsoft has not identified links between Storm-2603 and other known Chinese threat actors").

Active since March 2025 per Check Point Research. Standalone cluster paralleling velvet_ant + billbug + earth_alux in v0.1.154 China-aligned 2022-2025 enterprise persistence + exploitation operators cell.

Operational target profile
  • 400+ organizations compromised July 17-21, 2025 per Eye Security.
  • U.S. NNSA + Education Dept + Florida Revenue + Rhode Island Assembly high-profile victims per SC Media.
  • APAC + Latin America March-July 2025 prior per Check Point VirusTotal Operational attack architecture: (1) ToolShell SharePoint 4-CVE chain (cluster- defining): CVE-2025-49704 + CVE-2025-49706 original + CVE-2025-53770 + CVE-2025-53771 bypass (2) Warlock/X2anylock + LockBit Black + Babuk multi-ransomware (cluster-defining): unusual multi-RaaS deployment per Check Point + The Hacker News + Microsoft (3) Project AK47 toolset + AK47 C2 framework (cluster-defining): per Trustwave + Fortiguard (4) DLL hijacking + DLL sideloading + BYOVD (cluster-defining): signature defense evasion tradecraft (5) MachineKey theft from SharePoint signature (cluster-defining): per Microsoft (6) DNS-controlled backdoor (signature): per The Hacker News August 2025 (7) PsExec lateral movement (signature): per Picus Security (8) Uniform ransom notes signature: "How to decrypt my data.log" for X2anylock + "<Ransomware ID>.README.txt" for LockBit Black per Picus Security (9) Parallel exploitation by Linen + Violet + Salt Typhoon (signature): per Microsoft + Symantec October 2025 The cluster fills the March-2025-onward + ToolShell-SharePoint-zero-day-exploitation + Warlock-LockBit-Babuk-multi-ransomware-deployment + Project-AK47-toolset + China-ransomware-hybrid + MachineKeys-theft position in China-aligned 2022-2025 enterprise persistence + exploitation operators cell.

Aliases

14
storm-2603storm_2603storm 2603storm_2603_actorstorm-2603 suspected china-based threat actorstorm-2603 toolshell sharepoint zero-day exploitation july 2025storm-2603 cve-2025-49704 cve-2025-49706 cve-2025-53770 cve-2025-53771 sharepointstorm-2603 warlock ransomware x2anylockstorm-2603 lockbit black ransomware deploymentstorm-2603 babuk ransomware deploymentstorm-2603 ak47 c2 framework project ak47 toolsetstorm-2603 dll hijacking sideloading byovd bring your own vulnerable driverstorm-2603 unfading sea haze adjacent clusterwarlock ransomware warlock dark army x2anylock raas operation early 2024

Notable Campaigns

9
2025-2026Continued Industry Reference Status (2025-2026)
2025Storm-2603 Origin, March 2025 LATAM + APAC Ransomware Operations
2025Storm-2603 ToolShell SharePoint Zero-Day Mass Exploitation (July 2025)
2025Storm-2603 High-Profile Victims (July 2025)
2025Storm-2603 Warlock + LockBit Black + Babuk Multi-Ransomware Signature
2025Storm-2603 Project AK47 Toolset Signature
2025Storm-2603 Parallel ToolShell Exploitation by Linen + Violet + Salt Typhoon
2025Storm-2603 MachineKey Theft from SharePoint Servers Signature
2025Storm-2603 PsExec Lateral Movement Signature

Attribution & Reporting

Attributed by
Microsoft (canonical July 22-23, 2025 Disrupting active exploitation of on-premises SharePoint vulnerabilities blog + moderate-confidence China-based attribution)MITRE ATT&CK Campaign C0058 (canonical SharePoint ToolShell Exploitation tracking)Check Point Research (canonical August 2025 Before ToolShell, Exploring Storm-2603's Previous Ransomware Operations retrospective)The Hacker News (canonical August 6, 2025 Storm-2603 DNS-Controlled Backdoor in Warlock LockBit ransomware coverage)Trustwave SpiderLabs (canonical September 17, 2025 Storm-2603 Targeting SharePoint Vulnerabilities Critical Infrastructure Worldwide analysis)Picus Security (canonical January 2026 Storm-2603 Ransomware Campaign Microsoft SharePoint TTP analysis)SC Media (canonical July 23, 2025 China-backed Storm-2603 deployed ransomware via SharePoint zero-days coverage)Help Net Security (canonical July 24, 2025 Storm-2603 spotted deploying ransomware on exploited SharePoint servers)Fortiguard (canonical Storm-2603 Threat Actor profile)Symantec (canonical October 2025 Salt Typhoon Glowworm parallel ToolShell exploitation analysis)Eye Security (canonical 400+ organizations July 17-21 2025 attack waves tracking)
Key reporting
reportMicrosoft: Disrupting active exploitation of on-premises SharePoint vulnerabilities (July 22-23, 2025 updates), canonical Storm-2603 disclosure + moderate-confidence China-based attribution
reportMITRE ATT&CK: Campaign C0058, SharePoint ToolShell Exploitation (canonical campaign tracking)
reportCheck Point Research: Before ToolShell, Exploring Storm-2603's Previous Ransomware Operations (August 2025), canonical March-July 2025 retrospective
reportThe Hacker News: Storm-2603 Deploys DNS-Controlled Backdoor in Warlock and LockBit Ransomware Attacks (August 6, 2025)
reportTrustwave SpiderLabs: Storm-2603 Targeting SharePoint Vulnerabilities and Critical Infrastructure Worldwide (September 17, 2025)
reportPicus Security: Storm-2603 Ransomware Campaign Targets Microsoft SharePoint in 2025, Activity and TTP Analysis
reportSC Media: China-backed Storm-2603 deployed ransomware via SharePoint zero-days (July 23, 2025)
reportHelp Net Security: Storm-2603 spotted deploying ransomware on exploited SharePoint servers (July 24, 2025)
reportFortiguard: Storm-2603 Threat Actor Profile (canonical)
reportThe Hacker News: Chinese Threat Actors Exploit ToolShell SharePoint Flaw Weeks After Microsoft's July Patch (October 2025), canonical Salt Typhoon parallel exploitation
reportEye Security: canonical 400+ organizations July 17-21 2025 attack waves tracking
reportFrankie Sclafani Deepwatch: canonical CVE-2025-49704/49706/53770/53771 industry commentary

Operational

State sponsor

China-based, Microsoft moderate-confidence attribution per Microsoft Security Blog July 22-23, 2025. Operationally distinct from other known Chinese threat actors per Microsoft assessment ("Microsoft has not identified links between Storm-2603 and other known Chinese threat actors"). Unusual hybrid state-sponsored-espionage-with- cybercrime-ransomware-deployment profile per Fortiguard + Trustwave + Check Point.

Attribution chain: (1) Microsoft canonical July 22-23, 2025 disclosure + moderate-confidence China-based assessment: per Microsoft Security Blog: "The group that Microsoft tracks as Storm-2603 is assessed with moderate confidence to be a China-based threat actor. Microsoft has not identified links between Storm-2603 and other known Chinese threat actors. Microsoft tracks this threat actor in association with attempts to steal MachineKeys using the on- premises SharePoint vulnerabilities.

Although Microsoft has observed this threat actor deploying Warlock and Lockbit ransomware in the past, Microsoft is currently unable to confidently assess the threat actor's objectives." (2) Check Point Research canonical August 2025 retrospective + March 2025 prior activity: per Check Point Research + The Hacker News: "A previously unreported threat cluster, evidence gathered following an analysis of VirusTotal artifacts shows that the group may have been active since at least March 2025, deploying ransomware families like LockBit Black and Warlock together, something that's not observed commonly among established e-crime groups. Based on VirusTotal data, Storm-2603 likely targeted some organizations in Latin America throughout the first half of 2025, in parallel to attacking organizations in APAC." (3) MITRE ATT&CK Campaign C0058 canonical tracking: per MITRE: "Later patched and updated as CVE-2025-53770 and CVE-2025-53771, the ToolShell vulnerabilities were widely exploited including by China-based ransomware actor Storm-2603 and espionage actors Threat Group-3390 and ZIRCONIUM." (4) Trustwave SpiderLabs canonical September 2025 retrospective: per Trustwave: "Storm-2603 has been active since at least March 2025 and was most recently observed leveraging the ToolShell exploit chain... SpiderLabs' and other researchers' investigations into Storm-2603 uncovered the group's prior reliance on the Project AK47 toolset, which consists of ransomware, backdoor malware, and other tools." (5) Help Net Security canonical SharePoint exploitation context: per Help Net Security: "The threat actors in question are Chinese state- sponsored groups Linen Typhoon and Violet Typhoon, which concentrate on stealing intellectual property and espionage (respectively), and Storm-2603, another suspected China-based threat actor that seems primarily focused on deploying ransomware." (6) Symantec October 2025 Salt Typhoon parallel ToolShell exploitation: per The Hacker News: "CVE-2025-53770, assessed to be a patch bypass for CVE-2025-49704 and CVE-2025-49706, has been weaponized as a zero-day by three Chinese threat groups, including Linen Typhoon (aka Budworm), Violet Typhoon (aka Sheathminer), and Storm-2603...

Symantec indicate that a much wider range of Chinese threat actors have abused the vulnerability. This includes the Salt Typhoon (aka Glowworm) hacking group." Operational mission objective: Unusual hybrid: state-sponsored espionage TTPs (DLL sideloading + DLL hijacking + AK47 C2 framework + BYOVD signature China APT tradecraft) combined with financially motivated ransomware deployment (Warlock + LockBit Black + Babuk). MachineKeys theft from SharePoint servers signature objective indicating targeted information collection potentially preceding ransomware deployment.

Operational target profile
  • 400+ organizations compromised in July 17-21, 2025 ToolShell attack waves per Eye Security.
  • U.S. National Nuclear Security Administration (NNSA), U.S. Education Department, Florida Department of Revenue, Rhode Island General Assembly confirmed victims per SC Media.
  • APAC + Latin America geographic primary per Check Point VirusTotal analysis March-July 2025.
  • Multiple sectors including government + critical infrastructure + ransomware victims The cluster fills the March-2025-onward + ToolShell- SharePoint-zero-day-exploitation + Warlock-LockBit- Babuk-multi-ransomware-deployment + Project-AK47- toolset + China-ransomware-hybrid + MachineKeys- theft position in China-aligned 2022-2025 enterprise persistence + exploitation operators cell.
Motivations
china_state_sponsored_with_unusual_cybercrime_hybrid_profile, toolshell_sharepoint_zero_day_mass_exploitation_capability, warlock_lockbit_babuk_multi_ransomware_deployment_signature_capability, project_ak47_toolset_signature_capability, machinekey_theft_sharepoint_servers_signature_objective, dll_hijacking_sideloading_byovd_signature_tradecraft, financially_motivated_ransomware_attacks_distinct_from_typical_china_apt
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)58/60 · 96%
Analytics (MITRE CAR)33/60 · 55%
Runtime / container (Falco)8/60 · 13%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)19/60 · 31%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

0 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
MACHINEKEY THEFT SHAREPOINT SERVER SIGNATURE OBJECTIVESTORM 2603 ACTOR
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin