Storm-2603 Ransomware Targets Microsoft SharePoint Servers
Cybersecurity firm Picus Security reports that the Storm-2603 ransomware group has targeted Microsoft SharePoint servers, exploiting multiple vulnerabilities throughout 2025.

Cybersecurity firm Picus Security has identified Storm-2603, a financially motivated threat actor group, targeting Microsoft SharePoint servers with ransomware attacks during 2025. The group exploits several vulnerabilities to gain entry and deploy their malicious software.
Picus Labs' analysis indicates that during the first half of 2025, Storm-2603 conducted operations targeting organizations in Latin America and the APAC region. Significant activity was observed on July 18, 2025, when Microsoft reported Storm-2603 deploying ransomware by exploiting multiple SharePoint Server vulnerabilities, including CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771.
Storm-2603 has previously been associated with ransomware families such as LockBit Black and WarLock/X2anylock. Their tactics involve exploiting public-facing applications for initial access and utilizing tools like PsExec for lateral movement within networks. Additionally, the group employs "Bring Your Own Vulnerable Driver" (BYOVD) techniques to disable endpoint security products before ransomware deployment.
Picus Security advises organizations to continuously test and validate their security controls, potentially using platforms like the Picus Platform, to identify and strengthen defenses against threat actors like Storm-2603.