Skip to content
← All Threat Actors
Cybercrime high Eastern Europe (assessed)

Storm-2603

Financially motivated threat cluster (Microsoft designation) · Financial — ransomware and double extortion

Reports 1
Active Since 2025
Last Reported 3 Jul 2026
Sectors Targeted government, finance, professional-services, healthcare, education

Tactics, Techniques & Procedures (TTPs)

  • Enterprise software CVE exploitation for initial access — targeting large installed-base platforms shortly after CVE disclosure (CVE-2026-45659 SharePoint Server RCE exploited days after CISA KEV listing)
  • On-premises SharePoint Server deserialization RCE exploitation: crafted serialised objects triggering code execution as SharePoint application pool process
  • Rapid credential escalation: Domain Admin access via Active Directory attack paths within 24–48 hours of initial access
  • Warlock ransomware deployment: Windows and Linux/ESXi builds for cross-platform encryption
  • Rclone data exfiltration to cloud storage for double-extortion leverage before encryption
  • Broad sector targeting: any organisation with an exploitable enterprise software instance — government, legal, healthcare, financial services, higher education
  • Fast-moving operations: encryption deployed within 48 hours of gaining domain-level access in documented incidents

Known Targets

On-premises SharePoint Server deployments (government, legal, healthcare, financial services, education)European enterprises running on-premises Microsoft infrastructureNorth American organisations with internet-facing SharePoint portalsAsia-Pacific enterprise targets

Analyst Notes

Storm-2603 is a Microsoft-designated ransomware cluster operating Warlock ransomware, active across Europe, North America, and parts of Asia-Pacific through 2025–2026. The group's targeting model prioritises enterprise software with large installed bases and available exploits — SharePoint Server was added to CISA KEV on July 1, 2026 (CVE-2026-45659, CVSS 8.8) with a July 4 federal patch deadline, and exploitation by Storm-2603 was contemporaneous with the KEV listing. On-premises SharePoint deployments are concentrated in sectors with data sovereignty requirements or legacy infrastructure: government, legal, healthcare, financial services, and higher education — precisely the sectors with highest ransom leverage. The authentication requirement in CVE-2026-45659 is near-equivalent to pre-auth in externally facing SharePoint environments where phishing a single low-privilege credential is sufficient to stage the exploit.

Also Known As

Storm-2603 (Microsoft tracking designation)Warlock ransomware operators