Storm-2603
Storm-2603 (canonical Microsoft naming per July 22-23, 2025 SharePoint disclosure) is a Microsoft- tracked suspected China-based threat actor that emerged July 2025 with ToolShell SharePoint zero- day mass exploitation campaign weaponizing 4-CVE chain (CVE-2025-49704 + CVE-2025-49706 originally patched July 2025 + bypass variants CVE-2025-53770 + CVE-2025-53771 weaponized as zero-day post-patch) with unusual hybrid state-sponsored-with-cybercrime- ransomware profile.
China-based moderate-confidence attribution via Microsoft canonical disclosure ("The group that Microsoft tracks as Storm-2603 is assessed with moderate confidence to be a China- based threat actor. Microsoft has not identified links between Storm-2603 and other known Chinese threat actors. Microsoft tracks this threat actor in association with attempts to steal MachineKeys using the on-premises SharePoint vulnerabilities") + Check Point Research March 2025 prior activity retrospective ("evidence gathered following an analysis of VirusTotal artifacts shows that the group may have been active since at least March 2025, deploying ransomware families like LockBit Black and Warlock together, something that's not observed commonly among established e-crime groups") + MITRE ATT&CK Campaign C0058 + Trustwave SpiderLabs September 2025 + Fortiguard threat actor profile + Picus Security + SC Media + Help Net Security industry coverage.
standalone cluster paralleling velvet_ant + billbug + earth_alux in v0.1.154 China-aligned 2022-2025 enterprise persistence + exploitation operators cell; operational target profile 400+ organizations compromised in July 17-21, 2025 attack waves per Eye Security + high-profile victims including U.S. National Nuclear Security Administration (NNSA) + U.S. Education Department + Florida Department of Revenue + Rhode Island General Assembly per SC Media + APAC + Latin America March-July 2025 prior per Check Point VirusTotal analysis; operational attack architecture: (1) cluster- defining ToolShell SharePoint 4-CVE exploit chain with CVE-2025-49704 RCE + CVE-2025-49706 spoofing originally patched July 2025 + CVE-2025-53770 + CVE-2025-53771 bypass variants weaponized as zero- day post-patch.
(2) cluster-defining Warlock (aka X2anylock) + LockBit Black + Babuk multi- ransomware deployment with unusual operational sophistication per Check Point ("not observed commonly among established e-crime groups") + Picus Security uniform ransom notes signature ("How to decrypt my data.log" for X2anylock + LockBit README.txt naming)
(3) cluster-defining Project AK47 toolset including AK47 C2 framework + backdoor malware + supporting tools per Trustwave SpiderLabs + Fortiguard.
(4) cluster-defining DLL hijacking + DLL sideloading + BYOVD (Bring Your Own Vulnerable Driver) defense evasion tradecraft per Fortiguard.
(5) cluster-defining MachineKey theft from SharePoint servers signature objective per Microsoft enabling forged ViewState payloads + persistent authentication bypass on compromised SharePoint instances.
(6) signature DNS-controlled backdoor capability per The Hacker News August 2025.
(7) signature PsExec lateral movement living-off-the-land tradecraft per Picus Security.
(8) cluster-defining update. updatemicfosoft.com C2 domain typosquat signature per Check Point.
(9) signature parallel exploitation by Linen Typhoon (APT27) + Violet Typhoon (APT31) for espionage/IP theft + Salt Typhoon (Glowworm) deploying Zingdoor + ShadowPad + KrustyLoader against telecom + 2 African government bodies per Microsoft + Help Net Security + Symantec October 2025 establishing Storm-2603 as one of multiple Chinese clusters operationally weaponizing ToolShell SharePoint vulnerabilities.
cluster fills the March-2025- onward + ToolShell-SharePoint-zero-day-exploitation + Warlock-LockBit-Babuk-multi-ransomware-deployment + Project-AK47-toolset + China-ransomware-hybrid + MachineKeys-theft + 400+-organization-mass- compromise + U.S.-critical-infrastructure-victims position in China-aligned 2022-2025 enterprise persistence + exploitation operators cell; canonical illustration of 2025 China-aligned ransomware-hybrid actor + ToolShell SharePoint mass-exploitation + unusual multi-ransomware deployment + Project AK47 proprietary toolset + BYOVD defense evasion + MachineKeys theft + parallel-exploitation-with-Linen-Violet-Salt-Typhoon cited in essentially all subsequent 2025 SharePoint exploitation industry analyses through 2025-2026 period.