logo

SmarterTools Breached by Own SmarterMail Vulnerabilities

ID: c344717c-f4fe-529f-af69-23117b8efdae

STIX ID: report--c344717c-f4fe-529f-af69-23117b8efdae

Feed Name: The Cyber Express

Threat Score
75/100

Date Published: 2026-02-09

Date Updated: 2026-04-23

Author: Paul Shread

...
...

SmarterTools was breached after an unpatched SmarterMail VM was compromised—attributed to the Storm-2603 actor linked to Warlock ransomware—leveraging CVE-2026-23760 (and probes for CVE-2026-24423); attackers established persistence, often waited ~6–7 days before activating ransomware, targeted Active Directory for lateral movement, and abused legitimate/admin tools (Velociraptor, SimpleHelp, JWRapper, legacy WinRAR, etc.); network segmentation and Linux-heavy infrastructure limited impact and detections by SentinelOne helped prevent widespread encryption.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.