Storm-2603 is a likely China-based threat actor targeting on-premises SharePoint vulnerabilities to steal MachineKeys.
Analyst brief
Storm-2603 is a threat actor assessed with medium confidence by Microsoft to be China-based, but without identified links to other known Chinese groups. The actor primarily targets on-premises SharePoint vulnerabilities in attempts to steal MachineKeys. Although deployment of Warlock and Lockbit ransomware has been observed in the past, the group's current objectives are not confidently assessed. Defenders should focus on patching on-premises SharePoint systems, protecting MachineKeys, and monitoring for the actor's documented ransomware TTPs.
Storm-2603
unknown
The group Microsoft tracks as Storm-2603 is assessed with medium confidence to be a China-based threat actor. Microsoft has not identified links between Storm-2603 and other known Chinese threat actors. Microsoft tracks this threat actor in association with attempts to steal MachineKeys via the on-premises SharePoint vulnerabilities. Although Microsoft has observed this threat actor deploying Warlock and Lockbit ransomware in the past, Microsoft is currently unable to confidently assess the threat actor’s objectives. Additional actors may use these exploits to target unpatched on-premises SharePoint systems, further emphasizing the need for organizations to implement mitigations and security updates immediately.