CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Storm-2603 Exploits CVE-2026-23760 to Stage Warlock Ransomware

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 2200

As cited

Copy frozen at (site build).

ransomware

Storm-2603 Exploits CVE-2026-23760 to Stage Warlock Ransomware

ReliaQuest identified exploitation of CVE-2026-23760, a critical SmarterMail vulnerability, by the China-based threat actor Storm-2603 to bypass authentication and stage Warlock ransomware. The group abuses the software's Volume Mount feature for system control, then deploys Velociraptor, a legitimate forensic tool, to maintain persistence and prepare for ransomware deployment. The activity occurs alongside a separate wave of probes for CVE-2026-24423, indicating multiple threat vectors targeting internet-facing mail servers.

Why it matters: Organizations running SmarterMail must immediately upgrade to Build 9511 or later and implement network isolation around mail servers to block the attack chain from initial access through ransomware staging, as Storm-2603 is actively exploiting these vulnerabilities in production environments.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ransomware

Storm-2603 Exploits CVE-2026-23760 to Stage Warlock Ransomware

ReliaQuest identified exploitation of CVE-2026-23760, a critical SmarterMail vulnerability, by the China-based threat actor Storm-2603 to bypass authentication and stage Warlock ransomware. The group abuses the software's Volume Mount feature for system control, then deploys Velociraptor, a legitimate forensic tool, to maintain persistence and prepare for ransomware deployment. The activity occurs alongside a separate wave of probes for CVE-2026-24423, indicating multiple threat vectors targeting internet-facing mail servers.

Why it matters: Organizations running SmarterMail must immediately upgrade to Build 9511 or later and implement network isolation around mail servers to block the attack chain from initial access through ransomware staging, as Storm-2603 is actively exploiting these vulnerabilities in production environments.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary