The group Microsoft tracks as Storm-2603 is assessed with medium confidence to be a China-based threat actor. Microsoft has not identified links between Storm-2603 and other known Chinese threat actors. Microsoft tracks this threat actor in association with attempts to steal MachineKeys via the on-premises SharePoint vulnerabilities. Although Microsoft has observed this threat actor deploying Warlock and Lockbit ransomware in the past, Microsoft is currently unable to confidently assess the threat actor’s objectives. Additional actors may use these exploits to target unpatched on-premises SharePoint systems, further emphasizing the need for organizations to implement mitigations and security updates immediately.
Executive Summary
Storm-2603 is assessed with medium confidence as a China-based threat actor linked to attempts to steal MachineKeys through on-premises SharePoint vulnerabilities and past deployments of both Warlock and Lockbit ransomware. While Microsoft has not identified links to other known Chinese adversaries, the group's activities suggest a focus on exploiting unpatched systems and deploying ransomware, emphasizing the need for organizations to prioritize patching and security updates.
Goals & Targeting
The strategic objectives and targeting profile of Storm-2603 remain unclear due to limited intelligence. Their observed activities suggest an interest in financial gain, possibly through ransomware deployment (Warlock and Lockbit), though their primary motivation could also include espionage or disruption of services. The group appears to target sectors with unpatched SharePoint vulnerabilities, which may disproportionately affect small to medium-sized organizations lacking robust patch management processes. Target selection likely prioritizes ease of exploitation over strategic sectoral targeting, as evidenced by the focus on known vulnerabilities.
Enhanced Description
Storm-2603 is a cyber threat actor tracked by Microsoft, with a suspected base in China. The actor has been observed attempting to steal MachineKeys using vulnerabilities in on-premises SharePoint systems, which underscores their targeting of unpatched systems for exploitation. Additionally, Storm-2603 has been linked to the deployment of both Warlock and Lockbit ransomware, indicating an operational versatility that may suggest alignment with multiple motives or a modular approach to attack campaigns. Despite these observations, Microsoft lacks definitive evidence linking the group to other known Chinese-speaking threat actors, which makes their broader affiliations and objectives unclear. Storm-2603's targeting of vulnerable systems highlights a potential focus on exploiting known security gaps, a common tactic among less sophisticated actors or emerging groups seeking quick wins through easily accessible attack vectors.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Storm-2603's campaigns have focused on exploiting unpatched systems and deploying ransomware, targeting sectors where such vulnerabilities are prevalent. The group's operational tempo appears focused on opportunities presented by known exploits rather than large-scale campaigns. Notable past operations include attempts to exploit SharePoint vulnerabilities and the deployment of both Warlock and Lockbit ransomware in targeted attacks.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The confidence in the data on Storm-2603 is medium. While Microsoft has linked the group to specific activities—such as exploiting SharePoint vulnerabilities and deploying ransomware—the lack of clear ties to other known Chinese-speaking threat actors limits understanding of their broader affiliations, motivations, and operational capacities. Additional information gaps include the full range of tools used, detailed campaign patterns, and specific TTPs beyond those already observed.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics