Threadlinqs IntelligenceStart free

Threat actorChinaTracked since 2026-02

Storm-2603

As of 2026-10-04, Storm-2603 is a China-nexus threat actor tracked by Threadlinqs Intelligence across 8 threats spanning ransomware, vulnerability. ATT&CK coverage spans 101 techniques across 15 tactics in 8 of 8 tracked threats. Most-observed techniques: T1190 (Exploit Public-Facing Application), T1486 (Data Encrypted for Impact), T1505 (Server Software Component).

Tracked threats
87 critical · 1 high
First seen
2026-02-05
Last seen
2026-10-01
ATT&CK techniques
101across 8 of 8 threats
Related CVEs
18Referenced by its activity
Attribution
ChinaNation or origin
Nation: China · 8 tracked threat(s) · Categories: RANSOMWARE, VULNERABILITY

Activity timeline

Storm-2603 appears in 8 tracked threats between and ; the busiest month was 2026-07 with 5 reports.

ATT&CK techniques observed

101 techniques observed across 8 of 8 tracked threats · Stealth (formerly Defense Evasion) (15), Persistence (13), Discovery (12), Credential Access (11), Command and Control (9), Execution (7)
  • T1190 Exploit Public-Facing Application — Initial Accessobserved in 8 of 8 tracked threats
  • T1486 Data Encrypted for Impact — Impactobserved in 7 of 8 tracked threats
  • T1505 Server Software Component — Persistenceobserved in 7 of 8 tracked threats
  • T1685 Disable or Modify Tools — Defense Impairmentobserved in 7 of 8 tracked threats
  • T1059 Command and Scripting Interpreter — Executionobserved in 6 of 8 tracked threats
  • T1021 Remote Services — Lateral Movementobserved in 5 of 8 tracked threats
  • T1068 Exploitation for Privilege Escalation — Privilege Escalationobserved in 5 of 8 tracked threats
  • T1572 Protocol Tunneling — Command and Controlobserved in 5 of 8 tracked threats
  • T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 4 of 8 tracked threats
  • T1036 Masquerading — Stealth (formerly Defense Evasion)observed in 4 of 8 tracked threats
  • T1071 Application Layer Protocol — Command and Controlobserved in 4 of 8 tracked threats
  • T1078 Valid Accounts — Initial Accessobserved in 4 of 8 tracked threats
  • T1082 System Information Discovery — Discoveryobserved in 4 of 8 tracked threats
  • T1105 Ingress Tool Transfer — Command and Controlobserved in 4 of 8 tracked threats
  • T1203 Exploitation for Client Execution — Executionobserved in 4 of 8 tracked threats

Tracked threats

Related CVEs

18 CVEs referenced by tracked Storm-2603 activity