logo

Email Under Siege: Storm-2603 Exploits SmarterMail to Deploy Warlock Ransomware

ID: 105a1434-62fa-5776-a2cc-5daf91153db7

STIX ID: report--105a1434-62fa-5776-a2cc-5daf91153db7

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-02-13

Date Updated: 2026-04-23

Author: Ddos

...
...

ReliaQuest reports that Storm-2603 is actively exploiting a SmarterMail authentication-bypass vulnerability (CVE-2026-23760) — alongside a separately exploited RCE (CVE-2026-24423) — to reset admin credentials, abuse the software's Volume Mount feature for privileged command execution, deploy Velociraptor for persistence, and stage Warlock ransomware; rapid patch-to-exploit timelines and recommended mitigations (upgrade to Build 9511+, segmentation, and strict outbound firewalling) are emphasized.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.