Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Storm-2603

Description

The group Microsoft tracks as Storm-2603 is assessed with medium confidence to be a China-based threat actor. Microsoft has not identified links between Storm-2603 and other known Chinese threat actors. Microsoft tracks this threat actor in association with attempts to steal MachineKeys via the on-premises SharePoint vulnerabilities. Although Microsoft has observed this threat actor deploying Warlock and Lockbit ransomware in the past, Microsoft is currently unable to confidently assess the threat actor’s objectives. Additional actors may use these exploits to target unpatched on-premises SharePoint systems, further emphasizing the need for organizations to implement mitigations and security updates immediately.

AI Analysis

· 1 week ago

Executive Summary

Storm-2603 is assessed with medium confidence as a China-based threat actor linked to attempts to steal MachineKeys through on-premises SharePoint vulnerabilities and past deployments of both Warlock and Lockbit ransomware. While Microsoft has not identified links to other known Chinese adversaries, the group's activities suggest a focus on exploiting unpatched systems and deploying ransomware, emphasizing the need for organizations to prioritize patching and security updates.

Goals & Targeting

The strategic objectives and targeting profile of Storm-2603 remain unclear due to limited intelligence. Their observed activities suggest an interest in financial gain, possibly through ransomware deployment (Warlock and Lockbit), though their primary motivation could also include espionage or disruption of services. The group appears to target sectors with unpatched SharePoint vulnerabilities, which may disproportionately affect small to medium-sized organizations lacking robust patch management processes. Target selection likely prioritizes ease of exploitation over strategic sectoral targeting, as evidenced by the focus on known vulnerabilities.

Enhanced Description

Storm-2603 is a cyber threat actor tracked by Microsoft, with a suspected base in China. The actor has been observed attempting to steal MachineKeys using vulnerabilities in on-premises SharePoint systems, which underscores their targeting of unpatched systems for exploitation. Additionally, Storm-2603 has been linked to the deployment of both Warlock and Lockbit ransomware, indicating an operational versatility that may suggest alignment with multiple motives or a modular approach to attack campaigns. Despite these observations, Microsoft lacks definitive evidence linking the group to other known Chinese-speaking threat actors, which makes their broader affiliations and objectives unclear. Storm-2603's targeting of vulnerable systems highlights a potential focus on exploiting known security gaps, a common tactic among less sophisticated actors or emerging groups seeking quick wins through easily accessible attack vectors.

Key Capabilities

  • Exploitation of on-premises SharePoint vulnerabilities
  • Deployment of Warlock ransomware
  • Deployment of Lockbit ransomware
  • Ability to steal MachineKeys

MITRE ATT&CK Tactics

Exfiltration
Ransomware

ATT&CK Techniques

T1003.002
T1566.001

Software / Tooling

MachineKey stealer
Warlock ransomware
Lockbit ransomware

Campaigns & Victims

Storm-2603's campaigns have focused on exploiting unpatched systems and deploying ransomware, targeting sectors where such vulnerabilities are prevalent. The group's operational tempo appears focused on opportunities presented by known exploits rather than large-scale campaigns. Notable past operations include attempts to exploit SharePoint vulnerabilities and the deployment of both Warlock and Lockbit ransomware in targeted attacks.

IOC Patterns

  • Exploitation of on-premises SharePoint vulnerabilities
  • Deployment of Warlock or Lockbit ransomware

Recommended Actions

  • Ensure all on-premises SharePoint systems are patched with the latest security updates
  • Implement robust endpoint detection and response (EDR) solutions to detect malicious behavior
  • Conduct regular vulnerability scans to identify and remediate unpatched systems
  • Train users to recognize phishing attempts and suspicious activities

Suggested Tags

APT
China-based
Ransomware
Exploitation
Patch Management

Confidence Assessment

The confidence in the data on Storm-2603 is medium. While Microsoft has linked the group to specific activities—such as exploiting SharePoint vulnerabilities and deploying ransomware—the lack of clear ties to other known Chinese-speaking threat actors limits understanding of their broader affiliations, motivations, and operational capacities. Additional information gaps include the full range of tools used, detailed campaign patterns, and specific TTPs beyond those already observed.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Critical Infrastructure
APT
China-based
Exploitation
Patch Management

Details

Type
Unknown
Country of Origin
C
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.