logo

ToolShell under siege: Check Point analyzes Chinese APT Storm-2603

ID: 6daee73b-0516-56bc-a2b0-57b01edfa11e

STIX ID: report--6daee73b-0516-56bc-a2b0-57b01edfa11e

Feed Name: Security Affairs

Threat Score
85/100

Date Published: 2025-08-01

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Check Point and related reporting detail Storm-2603, a China-linked threat cluster that exploited four SharePoint vulnerabilities to deploy custom AK47 C2 backdoors (AK47HTTP and AK47DNS). The actors used DNS tunneling and HTTP-based C2, sideloaded DLLs, and leveraged a signed Antiy Labs driver (ServiceMouse.sys) and an Antivirus Terminator tool to kill security processes, ultimately deploying multiple ransomware variants including LockBit Black and Warlock against targets in Latin America and APAC in 2025.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.