# Storm-2603

> As of 2026-10-04, Storm-2603 is a China-nexus threat actor tracked by Threadlinqs Intelligence across 8 threats spanning ransomware, vulnerability. ATT&CK coverage spans 101 techniques across 15 tactics in 8 of 8 tracked threats. Most-observed techniques: T1190 (Exploit Public-Facing Application), T1486 (Data Encrypted for Impact), T1505 (Server Software Component).

- **Nation:** China
- **Tracked threats:** 8
- **Categories:** RANSOMWARE, VULNERABILITY
- **As of:** 2026-10-04

## ATT&CK techniques observed

101 techniques observed across 8 of 8 tracked threats. Tactics: Stealth (formerly Defense Evasion) (15), Persistence (13), Discovery (12), Credential Access (11), Command and Control (9), Execution (7).

- [T1190](https://intel.threadlinqs.com/technique/T1190) Exploit Public-Facing Application — Initial Access — observed in 8 of 8 tracked threats
- [T1486](https://intel.threadlinqs.com/technique/T1486) Data Encrypted for Impact — Impact — observed in 7 of 8 tracked threats
- [T1505](https://intel.threadlinqs.com/technique/T1505) Server Software Component — Persistence — observed in 7 of 8 tracked threats
- [T1685](https://intel.threadlinqs.com/technique/T1685) Disable or Modify Tools — Defense Impairment — observed in 7 of 8 tracked threats
- [T1059](https://intel.threadlinqs.com/technique/T1059) Command and Scripting Interpreter — Execution — observed in 6 of 8 tracked threats
- [T1021](https://intel.threadlinqs.com/technique/T1021) Remote Services — Lateral Movement — observed in 5 of 8 tracked threats
- [T1068](https://intel.threadlinqs.com/technique/T1068) Exploitation for Privilege Escalation — Privilege Escalation — observed in 5 of 8 tracked threats
- [T1572](https://intel.threadlinqs.com/technique/T1572) Protocol Tunneling — Command and Control — observed in 5 of 8 tracked threats
- [T1027](https://intel.threadlinqs.com/technique/T1027) Obfuscated Files or Information — Stealth (formerly Defense Evasion) — observed in 4 of 8 tracked threats
- [T1036](https://intel.threadlinqs.com/technique/T1036) Masquerading — Stealth (formerly Defense Evasion) — observed in 4 of 8 tracked threats
- [T1071](https://intel.threadlinqs.com/technique/T1071) Application Layer Protocol — Command and Control — observed in 4 of 8 tracked threats
- [T1078](https://intel.threadlinqs.com/technique/T1078) Valid Accounts — Initial Access — observed in 4 of 8 tracked threats
- [T1082](https://intel.threadlinqs.com/technique/T1082) System Information Discovery — Discovery — observed in 4 of 8 tracked threats
- [T1105](https://intel.threadlinqs.com/technique/T1105) Ingress Tool Transfer — Command and Control — observed in 4 of 8 tracked threats
- [T1203](https://intel.threadlinqs.com/technique/T1203) Exploitation for Client Execution — Execution — observed in 4 of 8 tracked threats

## Tracked threats

- [Warlock Ransomware Attackers Hit Water and Telecom Operators via SharePoint ToolShell Exploitation (Longlegs / Storm-2603)](https://intel.threadlinqs.com/threat/TL-2026-2833) — CRITICAL
- [July 2026 Patch Tuesday: Actively Exploited SharePoint RCE (CVE-2026-58644) and AD FS/SharePoint Zero-Days](https://intel.threadlinqs.com/threat/TL-2026-1437) — CRITICAL
- [CISA Warns of Trio of Actively Exploited SharePoint Server Flaws (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164)](https://intel.threadlinqs.com/threat/TL-2026-1378) — CRITICAL
- [CISA Warns of Active Exploitation of Three Microsoft SharePoint Server Vulnerabilities (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164)](https://intel.threadlinqs.com/threat/TL-2026-1361) — CRITICAL
- [CVE-2026-45659: SharePoint Deserialization RCE Added to CISA KEV Amid Storm-2603 Exploitation](https://intel.threadlinqs.com/threat/TL-2026-1061) — HIGH
- [CISA KEV Addition: Microsoft SharePoint Server Deserialization RCE (CVE-2026-45659) Actively Exploited by Storm-2603 / Warlock Ransomware](https://intel.threadlinqs.com/threat/TL-2026-1123) — CRITICAL
- [Warlock (Water Manaul / Storm-2603) Ransomware Campaign with BYOVD, Web Shells, and Multi-Channel Tunneling via SharePoint Exploitation](https://intel.threadlinqs.com/threat/TL-2026-0234) — CRITICAL
- [SmarterMail Dual-CVE Pre-Auth RCE Chain — CVE-2026-23760 Admin Password Reset + CVE-2026-24423 ConnectToHub RCE, CISA KEV, Mass Automated Exploitation, 2-Day Patch Weaponization via .NET Decompiler](https://intel.threadlinqs.com/threat/TL-2026-0103) — CRITICAL

## Related CVEs

18 CVEs referenced by tracked Storm-2603 activity.

- [CVE-2026-58644](https://intel.threadlinqs.com/cve/CVE-2026-58644)
- [CVE-2026-57092](https://intel.threadlinqs.com/cve/CVE-2026-57092)
- [CVE-2026-56164](https://intel.threadlinqs.com/cve/CVE-2026-56164)
- [CVE-2026-56155](https://intel.threadlinqs.com/cve/CVE-2026-56155)
- [CVE-2026-55040](https://intel.threadlinqs.com/cve/CVE-2026-55040)
- [CVE-2026-55008](https://intel.threadlinqs.com/cve/CVE-2026-55008)
- [CVE-2026-50661](https://intel.threadlinqs.com/cve/CVE-2026-50661)
- [CVE-2026-50522](https://intel.threadlinqs.com/cve/CVE-2026-50522)
- [CVE-2026-45659](https://intel.threadlinqs.com/cve/CVE-2026-45659)
- [CVE-2026-32201](https://intel.threadlinqs.com/cve/CVE-2026-32201)
- [CVE-2026-24423](https://intel.threadlinqs.com/cve/CVE-2026-24423)
- [CVE-2026-23760](https://intel.threadlinqs.com/cve/CVE-2026-23760)
- [CVE-2025-68947](https://intel.threadlinqs.com/cve/CVE-2025-68947)
- [CVE-2025-53771](https://intel.threadlinqs.com/cve/CVE-2025-53771)
- [CVE-2025-53770](https://intel.threadlinqs.com/cve/CVE-2025-53770)
- [CVE-2025-49706](https://intel.threadlinqs.com/cve/CVE-2025-49706)
- [CVE-2025-49704](https://intel.threadlinqs.com/cve/CVE-2025-49704)
- [CVE-2025-1055](https://intel.threadlinqs.com/cve/CVE-2025-1055)

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/Storm-2603
