Storm-2603 Exploits CVE-2026-23760 to Stage Warlock Ransomware
ID: 338c8a39-7477-5ffe-87c0-bdb6537987bb
STIX ID: report--338c8a39-7477-5ffe-87c0-bdb6537987bb
Feed Name: ReliaQuest Blog
Threat Score
ReliaQuest observed active exploitation of SmarterMail CVE-2026-23760 attributed to Storm-2603: attackers bypassed authentication via the password-reset API, abused the application’s Volume Mount feature to gain OS execution, and staged Warlock ransomware by installing Velociraptor for persistent C2; the report includes IOCs, observed infrastructure, and recommended mitigations (upgrade to Build 9511+, isolate mail servers, restrict outbound traffic).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
