Storm-2603
Financially motivated threat cluster (Microsoft designation) · Financial — ransomware and double extortion
Tactics, Techniques & Procedures (TTPs)
- Enterprise software CVE exploitation for initial access — targeting large installed-base platforms shortly after CVE disclosure (CVE-2026-45659 SharePoint Server RCE exploited days after CISA KEV listing)
- On-premises SharePoint Server deserialization RCE exploitation: crafted serialised objects triggering code execution as SharePoint application pool process
- Rapid credential escalation: Domain Admin access via Active Directory attack paths within 24–48 hours of initial access
- Warlock ransomware deployment: Windows and Linux/ESXi builds for cross-platform encryption
- Rclone data exfiltration to cloud storage for double-extortion leverage before encryption
- Broad sector targeting: any organisation with an exploitable enterprise software instance — government, legal, healthcare, financial services, higher education
- Fast-moving operations: encryption deployed within 48 hours of gaining domain-level access in documented incidents
Known Targets
Analyst Notes
Storm-2603 is a Microsoft-designated ransomware cluster operating Warlock ransomware, active across Europe, North America, and parts of Asia-Pacific through 2025–2026. The group's targeting model prioritises enterprise software with large installed bases and available exploits — SharePoint Server was added to CISA KEV on July 1, 2026 (CVE-2026-45659, CVSS 8.8) with a July 4 federal patch deadline, and exploitation by Storm-2603 was contemporaneous with the KEV listing. On-premises SharePoint deployments are concentrated in sectors with data sovereignty requirements or legacy infrastructure: government, legal, healthcare, financial services, and higher education — precisely the sectors with highest ransom leverage. The authentication requirement in CVE-2026-45659 is near-equivalent to pre-auth in externally facing SharePoint environments where phishing a single low-privilege credential is sufficient to stage the exploit.
Also Known As
MITRE ATT&CK Techniques