Storm-2603 is misusing DFIR tools to stay inside networks. It’s a sharp reminder: even your defenses can be turned against you. #DFIR #CyberThreats #Storm2603 #CyberDefense www.darkreading.com/cybersecurit...
⚠️ Storm-2603 hijacks Velociraptor for multi-ransomware ops
Sophos and Cisco Talos found Storm-2603 weaponizing #Velociraptor via ToolShell exploits to deploy LockBit, Warlock, and Babuk ransomware.
#ransomNews #ransomware #storm2603
ClayRat e Velociraptor ridefiniscono le minacce cyber: spyware Android e tool forensics usati da Storm-2603 in attacchi ransomware globali.
#Android #CiscoTalos #ClayRat #Ransomware #spyware #Storm2603 #Velociraptor #Zimperium
www.matricedigitale.it/2025/10/09/c...
Warlock is a #ransomware based on the leaked #LockBit code, & is used by the Chinese #APT group #Storm2603 in the recent #ToolShell campaign. Protect yourself by deploying our public #YARArules: https://bit.ly/3x34FdW
Untersuchung der bisherigen Ransomware-Operationen der nicht-dokumentierten Gruppe STORM-2603
#AntivirusTerminator @CheckPointSW @CheckPointResearch #Cyberbedrohung #Cybersecurity #Cybersicherheit #Ransomware #Sharepoint #Sicherheitslücke #STORM2603
netzpalaver.de/2025/...
Alert: Storm-2603 exploits SharePoint flaws to deploy Warlock ransomware. Ensure your systems are patched and security measures are in place. #CyberSecurity #Ransomware #SharePoint #Storm2603 Link: thedailytechfeed.com/storm-2603-e...
Storm-2603 evolve nel ransomware con ak47c2 e ToolShell, puntando settori sensibili tramite exploit e backdoor avanzate.
#ak47c2 #backdoor #CheckPointResearch #Ransomware #Storm2603 #ToolShell
www.matricedigitale.it/2025/08/01/s...
~Checkpoint~
Threat actor Storm-2603 linked to earlier LockBit & Warlock ransomware attacks using a custom C2 framework dubbed 'ak47c2'.
-
IOCs: updatemicfosoft[. ]com, microsfot[. ]org
-
#Ransomware #Storm2603 #ThreatIntel
2/2:
Attackers use Mimikatz, PsExec, WMI & GPOs for lateral movement and ransomware delivery. Microsoft urges urgent patching. CISA confirms active exploitation of CVE-2025-53770.
#CyberSecurity #Ransomware #Storm2603 #ZeroDay #Microsoft #SharePoint #Infosec #APT
Attackers use Mimikatz, PsExec, WMI & GPOs for lateral movement and ransomware delivery. Microsoft urges urgent patching. CISA confirms active exploitation of CVE-2025-53770.
#PotatoSecurity #Ransomware #Storm2603 #ZeroDay #Microsoft #SharePoint #Infosec #APT
💥 Microsoft meldet 400 kompromittierte Organisationen durch SharePoint-Schwachstellen – auch US-Atombehörde betroffen.
👉 www.speicherguide.de/news/microso...
#Cybersicherheit #Storm2603 #ITSecurity #Ransomware #Sicherheitslücke #Cyberangriff
#Microsoft: #SharePoint attacks now officially include #ransomware infections
www.theregister.com/2025/07/24/m...
Redmond confirms #Storm2603 is abusing now-patched #vulnerability.
#CyberSecurity #InfoSec #CyberCrime #MicrosoftSharepoint
Alert: Storm-2603 exploits SharePoint vulnerabilities to deploy Warlock ransomware. Ensure your systems are updated and secure. #CyberSecurity #Ransomware #SharePoint #Storm2603 Link: thedailytechfeed.com/storm-2603-e...
#US #nuclear weapons agency among 400 organisations breached by #China #hacker groups — #LinenTyphoon, #VioletTyphoon, and #Storm2603.
www.theguardian.com/technology/2...
#Microsoft servers hacked by Chinese groups, says #techgiant
www.bbc.co.uk/news/article...
Threat actors hack some #MicrosoftSharePoint servers & target data of business users.
#BigTech #CyberSecurity #InfoSec #CyberCrime #LinenTyphoon #VioletTyphoon #Storm2603
⚠️重大⚠️警告⚠️
Microsoft「SharePointをオンプレミスで使用している場合は侵害されたと考えて。中国から世界規模の大規模なサイバー攻撃」
#LinenTyphoon #VioletTyphoon #Storm2603
詳細を解説。ご視聴はこちら👇
youtu.be/H1gNpN60wRw
⚠️Serious⚠️Warning⚠️
Microsoft: "If you're using SharePoint on-premise, assume you've been breached. Large-scale global cyber attack from China"