Activity timeline
Storm-2603 appears in 8 tracked threats between and ; the busiest month was 2026-07 with 5 reports.
ATT&CK techniques observed
- T1190 Exploit Public-Facing Application — Initial Accessobserved in 8 of 8 tracked threats
- T1486 Data Encrypted for Impact — Impactobserved in 7 of 8 tracked threats
- T1505 Server Software Component — Persistenceobserved in 7 of 8 tracked threats
- T1685 Disable or Modify Tools — Defense Impairmentobserved in 7 of 8 tracked threats
- T1059 Command and Scripting Interpreter — Executionobserved in 6 of 8 tracked threats
- T1021 Remote Services — Lateral Movementobserved in 5 of 8 tracked threats
- T1068 Exploitation for Privilege Escalation — Privilege Escalationobserved in 5 of 8 tracked threats
- T1572 Protocol Tunneling — Command and Controlobserved in 5 of 8 tracked threats
- T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 4 of 8 tracked threats
- T1036 Masquerading — Stealth (formerly Defense Evasion)observed in 4 of 8 tracked threats
- T1071 Application Layer Protocol — Command and Controlobserved in 4 of 8 tracked threats
- T1078 Valid Accounts — Initial Accessobserved in 4 of 8 tracked threats
- T1082 System Information Discovery — Discoveryobserved in 4 of 8 tracked threats
- T1105 Ingress Tool Transfer — Command and Controlobserved in 4 of 8 tracked threats
- T1203 Exploitation for Client Execution — Executionobserved in 4 of 8 tracked threats
Tracked threats
- Warlock Ransomware Attackers Hit Water and Telecom Operators via SharePoint ToolShell Exploitation (Longlegs / Storm-2603)CRITICAL
- July 2026 Patch Tuesday: Actively Exploited SharePoint RCE (CVE-2026-58644) and AD FS/SharePoint Zero-DaysCRITICAL
- CISA Warns of Trio of Actively Exploited SharePoint Server Flaws (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164)CRITICAL
- CISA Warns of Active Exploitation of Three Microsoft SharePoint Server Vulnerabilities (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164)CRITICAL
- CVE-2026-45659: SharePoint Deserialization RCE Added to CISA KEV Amid Storm-2603 ExploitationHIGH
- CISA KEV Addition: Microsoft SharePoint Server Deserialization RCE (CVE-2026-45659) Actively Exploited by Storm-2603 / Warlock RansomwareCRITICAL
- Warlock (Water Manaul / Storm-2603) Ransomware Campaign with BYOVD, Web Shells, and Multi-Channel Tunneling via SharePoint ExploitationCRITICAL
- SmarterMail Dual-CVE Pre-Auth RCE Chain — CVE-2026-23760 Admin Password Reset + CVE-2026-24423 ConnectToHub RCE, CISA KEV, Mass Automated Exploitation, 2-Day Patch Weaponization via .NET DecompilerCRITICAL