Threat Intelligence / Actor / Storm-2603
Storm-2603
As of 2026-07-26, Storm-2603 is a China-nexus threat actor tracked by Threadlinqs Intelligence across 7 threats spanning vulnerability, ransomware. Also known as CL-CRI-1040, CamoFei, ChamelGang, AK47.
Also known as: Storm-2603, CL-CRI-1040, CamoFei, ChamelGang, AK47, X2ANYLOCK, wlteaml, Gold Salem, Warlock Group
Tracked threats
- July 2026 Patch Tuesday: Actively Exploited SharePoint RCE (CVE-2026-58644) and AD FS/SharePoint Zero-Days — CRITICAL
- CISA Warns of Trio of Actively Exploited SharePoint Server Flaws (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164) — CRITICAL
- CISA Warns of Active Exploitation of Three Microsoft SharePoint Server Vulnerabilities (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164) — CRITICAL
- CISA KEV Addition: Microsoft SharePoint Server Deserialization RCE (CVE-2026-45659) Actively Exploited by Storm-2603 / Warlock Ransomware — CRITICAL
- CVE-2026-45659: SharePoint Deserialization RCE Added to CISA KEV Amid Storm-2603 Exploitation — HIGH
- Warlock (Water Manaul / Storm-2603) Ransomware Campaign with BYOVD, Web Shells, and Multi-Channel Tunneling via SharePoint Exploitation — CRITICAL
- SmarterMail Dual-CVE Pre-Auth RCE Chain — CVE-2026-23760 Admin Password Reset + CVE-2026-24423 ConnectToHub RCE, CISA KEV, Mass Automated Exploitation, 2-Day Patch Weaponization via .NET Decompiler — CRITICAL
Full actor intelligence — infrastructure, IOCs, detection coverage and operator fingerprints — is available via the Threadlinqs MCP server (Purple tier). View plans →