Storm-2603 Using Custom Malware That Leverages BYOVD to Tamper with Endpoint Protections
ID: 506a07db-e182-5fe5-8bef-e84d06d1d514
STIX ID: report--506a07db-e182-5fe5-8bef-e84d06d1d514
Feed Name: cybersecurityNews.com
Storm-2603 is a newly identified ransomware-focused threat actor that exploited multiple SharePoint Server CVEs to gain access, uses a custom Command-and-Control framework ('ak47c2' with ak47http and ak47dns), and employs an 'Antivirus Terminator' BYOVD tool that leverages a signed vulnerable driver to neutralize endpoint protections. The group has deployed multiple ransomware families (LockBit Black, Warlock), used DLL hijacking for execution, and targeted organizations across Latin America and the Asia-Pacific region during 2025.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
