logo

Storm-2603 Leverages Custom Malware and BYOVD to Evade Endpoint Protections

ID: 88fe0607-2c63-57c8-be17-3330bd9dd037

STIX ID: report--88fe0607-2c63-57c8-be17-3330bd9dd037

Feed Name: Cyber Press

Threat Score
88/100

Date Published: 2025-08-02

Date Updated: 2026-04-19

Author: Priya

...
...

Check Point Research attributes a sophisticated campaign to Storm-2603, a Chinese APT active in Latin America and Asia-Pacific in 2025, which leverages a legitimately signed Antiy driver (renamed ServiceMouse.sys) via BYOVD to disable endpoint protections, deploys a custom ak47c2 C2 (HTTP/DNS) with encrypted communications, and simultaneously distributes multiple ransomware families (e.g., LockBit Black, Warlock/x2anylock) using techniques like DLL hijacking, lateral movement tools (PsExec, masscan), and provides numerous indicators (domains and file hashes).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.