Uptime Hamster: 10d 19h 55mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza Storm-2603

Storm-2603

0 incidentes 0 paises 0 sectores ransomware Eastern Europe Ultimo: -
Aliases: DEV-2603
Ver en IntelTracker → APTTrail →
Storm-2603 is a China-based threat actor, assessed with moderate confidence to be primarily financially motivated, that emerged in early 2025 and is also known for exhibiting espionage-like tactics. This group is distinct from, but operates in the same ecosystem as, state-backed Chinese groups like Linen Typhoon and Violet Typhoon, and is also tracked as CL-CRI-1040 by Palo Alto. Storm-2603 is particularly notable for exploiting vulnerabilities in on-premises Microsoft SharePoint servers as part of the "ToolShell" exploit chain and for deploying multiple ransomware families, including Warlock and LockBit Black, often within the same campaign. The group has also been observed using a custom command-and-control framework dubbed "AK47 C2" and employing Bring Your Own Vulnerable Driver (BYOVD) techniques for defense evasion.

Aliases del actor

DEV-2603

Actores similares

devmanransomware · 184stormousransomware · 177crimson-sandstormactor · 1Network Devicesactor · 1Compromise Software Dependencies and Development Toolsactor · 1Device Driver Discoveryactor · 1Storm-1811actor · 1Storm-0501apt · 1Dust Stormapt · 1CS FQL: 32. Detect Data Exfiltration via external storage devicesactor · 1
Tecnicas MITRE
T1190, T1059.001, T1505.003, T1071.001
Tipo
ransomware
Pais origen
Eastern Europe
Motivacion
-
Impacto
58
Actualizado
Sat, 20 Ju

Paises objetivo (SOCRadar)

ArgentinaAustraliaBrazilCanadaChinaGermanySpainFranceUnited KingdomGreenland

Sectores objetivo (SOCRadar)

Other Information ServicesSoftware PublishersEnterprises & HoldingManufacturingPublic AdministrationEducational ServicesSpace & DefenseEnergy & Utilities InsuranceNational Security&International Affairs