Storm-2603 Deploys DNS-Controlled Backdoor in Warlock and LockBit Ransomware Attacks
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-49704 +1 in the same advisory: …49706 | Authenticated Code Injection RCE in Microsoft SharePoint CVE-2025-49704 is a code injection vulnerability (CWE-94) in Microsoft SharePoint that allows an authorized (authenticated) attacker to execute arbitrary code on the server over the network, by sending requests whose attacker-controlled input SharePoint executes as code. It can be chained with CVE-2025-49706, and Microsoft subsequently issued CVE-2025-53770 as a patch bypass of the original CVE-2025-49704 fix, meaning the CVE-2025-53770 updates provide stronger protection and should be treated as the definitive remediation. Successful exploitation yields remote code execution on the SharePoint server, and CISA added the flaw to the KEV on 2025-07-22 with known ransomware use. Organizations running on-premises SharePoint Server are affected; CISA directs owners of public-facing servers running EOL/EOS versions (SharePoint Server 2013 and earlier) to disconnect them, and operators of supported versions to apply the CISA and vendor mitigations and updates, with cloud SharePoint services governed by BOD 22-01. Exploitation is confirmed in the wild and EPSS assigns a 100% probability of exploitation within 30 days (top percentile), although no public proof-of-concept code is documented. Do: Apply Microsoft's SharePoint Server updates for CVE-2025-53770, which supersede the original CVE-2025-49704 fixes with more robust protection, prioritizing internet-facing servers. Disconnect public-facing SharePoint servers running EOL/EOS versions (SharePoint Server 2013 and earlier), and for supported versions follow the CISA and vendor mitigations, with cloud services handled per BOD 22-01. Because in-the-wild exploitation and ransomware use are confirmed, hunt for indicators of compromise and ransomware activity on exposed SharePoint servers. | 8.8 group max | 100% | KEV ransomware |
| masstens of thousands of internet-exposed SharePoint servers per public scans, within a total on-premises install base plausibly exceeding 100,000 deployments… |
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | updatemicfosoft.com | at uses DNS for command-and-control with the domain "update.updatemicfosoft[.]com." The backdoor is part of the AK47 C2 framework, alongsid |
Full article723 words · extracted from thehackernews.com · click to collapse
The threat actor linked to the exploitation of the recently disclosed security flaws in Microsoft SharePoint Server is using a bespoke command-and-control (C2) framework called AK47 C2 (also spelled ak47c2) in its operations.
The framework includes at least two different types of clients, HTTP-based and Domain Name System (DNS)-based, which have been dubbed AK47HTTP and AK47DNS, respectively, by Check Point Research.
The activity has been attributed to Storm-2603, which, according to Microsoft, is a suspected China-based threat actor that has leveraged the SharePoint flaws – CVE-2025-49706 and CVE-2025-49704 (aka ToolShell) – to deploy Warlock (aka X2anylock) ransomware.
A previously unreported threat cluster, evidence gathered following an analysis of VirusTotal artifacts shows that the group may have been active since at least March 2025, deploying ransomware families like LockBit Black and Warlock together – something that's not observed commonly among established e-crime groups.
"Based on VirusTotal data, Storm-2603 likely targeted some organizations in Latin America throughout the first half of 2025, in parallel to attacking organizations in APAC," Check Point said.
The attack tools used by the threat actor includes legitimate open-source and Windows utilities like masscan, WinPcap, SharpHostInfo, nxc, and PsExec, as well as a custom backdoor ("dnsclient.exe") that uses DNS for command-and-control with the domain "update.updatemicfosoft[.]com."
The backdoor is part of the AK47 C2 framework, alongside AK47HTTP, that's employed to gather host information and parse DNS or HTTP responses from the server and execute them on the infected machine via "cmd.exe." The initial access pathway used in these attacks are unknown.
A point worth mentioning here is that the aforementioned infrastructure was also flagged by Microsoft as used by the threat actor as a C2 server to establish communication with the "spinstall0.aspx" web shell. In addition to the open-source tools, Storm-2603 has been found to distribute three additional payloads -
- 7z.exe and 7z.dll, the legitimate 7-Zip binary that's used to sideload a malicious DLL, which delivers Warlock
- bbb.msi, an installer that uses clink_x86.exe to sideload "clink_dll_x86.dll," which leads to LockBit Black deployment
Check Point said it also discovered another MSI artifact uploaded to VirusTotal in April 2025 that's used to launch Warlock and LockBit ransomware, and also drop a custom antivirus killer executable ("VMToolsEng.exe") that employs the bring your own vulnerable driver (BYOVD) technique to terminate security software using ServiceMouse.sys, a third-party driver provided by Chinese security vendor Antiy Labs.
Ultimately, Storm-2603's exact motivations remain unclear at this stage, making it harder to determine if it's espionage-focused or driven by profit motives. However, it bears noting that there have been instances where nation-state actors from China, Iran, and North Korea have deployed ransomware on the side.
"We tend to assess it is a financially motivated actor, but with this, we can't also exclude the option that this is a dual motivation actor, both espionage and financially motivated," Sergey Shykevich, Threat Intelligence Group Manager at Check Point, told The Hacker News.
"Storm-2603 leverages BYOVD techniques to disable endpoint defenses and DLL hijacking to deploy multiple ransomware families – blurring the lines between APT and criminal ransomware operations," Check Point added. "The group also uses open-source tools like PsExec and masscan, signaling a hybrid approach seen increasingly in sophisticated attacks."
More Details About Storm-2603 Emerge
Palo Alto Networks Unit 42, which is tracking Storm-2603 under the moniker CL-CRI-1040, said it has also observed the threat activity cluster using AK47 C2 prior to the exploitation of ToolShell flaws in Microsoft SharePoint Server.
"CL-CRI-1040 was formerly associated with a LockBit 3.0-affiliate and has recently been operating a double-extortion data leak site known as Warlock," the company said.
Describing AK47 C2 as a multi-protocol supporting backdoor, Unit 42 said the tool comes with capabilities to execute arbitrary commands received via DNS and HTTP. Both the variants are assessed to be under development since at least early March 2025.
The cybersecurity company also pointed out that it has not found any common indicators to link Warlock ransomware and X2anylock (aka AK47 ransomware), and that it cannot "conclusively" ascertain if the two ransomware strains are one and the same.
(The story was updated after publication on August 6, 2025, to include additional insights about AK47 C2 from Palo Alto Networks Unit 42.)
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2025/08/storm-2603-exploits-sharepoint-flaws-to.html