Storm-2603 Leverages Custom Malware and BYOVD to Evade Endpoint Protections
ID: 88fe0607-2c63-57c8-be17-3330bd9dd037
STIX ID: report--88fe0607-2c63-57c8-be17-3330bd9dd037
Feed Name: Cyber Press
Check Point Research attributes a sophisticated campaign to Storm-2603, a Chinese APT active in Latin America and Asia-Pacific in 2025, which leverages a legitimately signed Antiy driver (renamed ServiceMouse.sys) via BYOVD to disable endpoint protections, deploys a custom ak47c2 C2 (HTTP/DNS) with encrypted communications, and simultaneously distributes multiple ransomware families (e.g., LockBit Black, Warlock/x2anylock) using techniques like DLL hijacking, lateral movement tools (PsExec, masscan), and provides numerous indicators (domains and file hashes).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
