Storm-2603 Ransomware Campaign Targets Microsoft SharePoint in 2025: Activity and TTP Analysis
ID: ca06d52c-6da3-5615-b148-387b9b5345d3
STIX ID: report--ca06d52c-6da3-5615-b148-387b9b5345d3
Feed Name: Resources-2
Storm-2603 is a financially motivated ransomware group active in 2025 that has been observed deploying LockBit Black and WarLock/X2anylock by exploiting multiple Microsoft SharePoint Server CVEs; Microsoft reported active exploitation on July 18, 2025. The report maps the group's TTPs — including public-facing application exploitation, PsExec for remote execution, BYOVD driver abuse to disable defenses, DLL search order hijacking to load ransomware, mass internal scanning with masscan, discovery with SharpHostInfo, and C2 via HTTP and DNS tunneling — and recommends validating defenses against these techniques using the Picus Security Validation Platform.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
