logo

Colt Technology Services gets ransomware’d via SharePoint initial access— some learning points

ID: be3d43bc-19b2-5b53-bc8f-0aaac1464111

STIX ID: report--be3d43bc-19b2-5b53-bc8f-0aaac1464111

Feed Name: DoublePulsar

Threat Score
75/100

Date Published: 2025-08-22

Date Updated: 2026-04-19

Author: Kevin Beaumont

...
...

A report-style post describes a Warlock (STORM-2603) ransomware/extortion incident against Colt where attackers exploited a SharePoint on‑prem vulnerability (CVE-2025-53770), installed a webshell (spinstall0.aspx), exfiltrated roughly 400k documents, and advertised the data for sale; the author criticizes delayed breach disclosure, highlights telemetry and LeakIX findings, and provides operational lessons on transparency, segmentation, and attack surface management.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.