Close Menu
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
What's Hot

Jalen Brunson defends Monica McNutt after backlash from Taylor Swift

Tullamarines cover Fleetwood Mac with ‘Like a Version’

Taylor Swift transforms her date night style into velvet luxury

Facebook X (Twitter) Instagram
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
Facebook X (Twitter) Instagram
FYMOUS News
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
FYMOUS News
Home » Storm-2603 exploits a flaw in SharePoint to deploy Warlock ransomware on unearned systems
Celebrities

Storm-2603 exploits a flaw in SharePoint to deploy Warlock ransomware on unearned systems

By July 24, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

July 24, 2025Ravi LakshmananVulnerability/Ransomware

Warlock ransomware

Microsoft has revealed that one of the threat actors behind the aggressive exploitation of SharePoint flaws is deploying Warlock ransomware on target systems.

The tech giant said in an update shared on Wednesday that the findings are based on “analysis and increased threat intelligence from continuous surveillance of Storm-2603’s exploitation activities.”

The threat actors due to financially motivated activities are suspected of being a China-based threat actor who has been known to drop warlocks and rock bit ransomware in the past.

The attack chain involves exploitation of CVE-2025-49706, a spoofing vulnerability, and CVE-2025-49704, a remote code execution vulnerability, targeting an accrued on-premises SharePoint server to deploy a spinstall 0.aspx web shell payload.

Cybersecurity

“This initial access is used to run command execution using the W3WP.EXE process that supports SharePoint,” Microsoft said. “Storm-2603 starts a set of discovery commands, including Whoami, to enumerate the user’s context and verify the privilege level.”

Attacks are characterized by using CMD.exe and batch scripts when threat actors dig deep into the target network, but Services.exe is abused to change the Windows registry to turn off Microsoft Defender protection.

In addition to leverage to continue Spinstall0.aspx, it has been observed that Storm-2603 creates scheduled tasks and modifys Internet Information Services (IIS) components to launch what Microsoft described as a suspicious .NET assembly. These actions are designed to ensure continuous access, even when victims take steps to connect the initial access vector.

Other notable aspects of the attack include the deployment of Mimikats to target local security station subsystem services (LSASS) memory to harvest credentials, followed by lateral movements using PSEXEC and Impacket Toolkit.

“We’re observing Storm-2603 modifying Group Policy Objects (GPOs) to distribute Warlock ransomware in compromised environments,” Microsoft said.

Warlock ransomware

As a mitigation, users are advised to follow the steps below –

Upgrading to a supported version of on-premises version Upgrading to a supported version of Microsoft SharePoint Server Apply the latest security updates Apply the latest security updates by applying the latest security updates to ensure that the anti-malware scan interface is turned on and that you correctly deploy Microsoft Defenderdenderdderd on the endpoint. Implement an incident response plan (after installing new security updates)

Cybersecurity

The development has already claimed at least 400 victims as the SharePoint server flaws are under massive exploitation. Linen Timpon (aka APT27) and Violet Typhoon (aka APT31) are two other Chinese hacking groups linked to malicious activities. China has denied the allegations.

“Cybersecurity is a common challenge facing all countries and needs to be addressed jointly through dialogue and cooperation,” said Guo Jiakun, spokesman for China’s Ministry of Foreign Affairs. “China will oppose and fight against hacking activities according to the law, and at the same time oppose smears and attacks against China under the excuses of cybersecurity issues.”


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleBurial of a tall warrior from 3,800 years old, buried in four tapered areas excavated in Azerbaijan
Next Article £30 million for green fuels and technology for decarbonized transport

Related Posts

Taylor Swift transforms her date night style into velvet luxury

June 14, 2026

Nina Dobrev takes on bridal trends beyond white satin in Taorna

June 14, 2026

Katie Holmes, Kiki Palmer, etc.

June 12, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Jalen Brunson defends Monica McNutt after backlash from Taylor Swift

Tullamarines cover Fleetwood Mac with ‘Like a Version’

Taylor Swift transforms her date night style into velvet luxury

Nina Dobrev takes on bridal trends beyond white satin in Taorna

Trending Posts

Jalen Brunson defends Monica McNutt after backlash from Taylor Swift

June 14, 2026

Tullamarines cover Fleetwood Mac with ‘Like a Version’

June 14, 2026

Taylor Swift transforms her date night style into velvet luxury

June 14, 2026

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to The FYMOUS, a modern digital media platform dedicated to celebrities, artists, influencers, brands, entertainment culture, and the growing TwinH ecosystem.

We bring audiences closer to the people, stories, trends, and collaborations shaping today’s culture. From exclusive celebrity news and music releases to influencer highlights, brand partnerships, and TwinH activations, The FYMOUS delivers engaging content designed for the next generation of digital audiences.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.