As cited
Copy frozen at (site build).
ransomware
Storm-2603 Exploits CVE-2026-23760 to Stage Warlock Ransomware
ReliaQuest identified exploitation of CVE-2026-23760, a critical SmarterMail vulnerability, by the China-based threat actor Storm-2603 to bypass authentication and stage Warlock ransomware. The group abuses the software's Volume Mount feature for system control, then deploys Velociraptor, a legitimate forensic tool, to maintain persistence and prepare for ransomware deployment. The activity occurs alongside a separate wave of probes for CVE-2026-24423, indicating multiple threat vectors targeting internet-facing mail servers.
Why it matters: Organizations running SmarterMail must immediately upgrade to Build 9511 or later and implement network isolation around mail servers to block the attack chain from initial access through ransomware staging, as Storm-2603 is actively exploiting these vulnerabilities in production environments.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
ransomware
Storm-2603 Exploits CVE-2026-23760 to Stage Warlock Ransomware
ReliaQuest identified exploitation of CVE-2026-23760, a critical SmarterMail vulnerability, by the China-based threat actor Storm-2603 to bypass authentication and stage Warlock ransomware. The group abuses the software's Volume Mount feature for system control, then deploys Velociraptor, a legitimate forensic tool, to maintain persistence and prepare for ransomware deployment. The activity occurs alongside a separate wave of probes for CVE-2026-24423, indicating multiple threat vectors targeting internet-facing mail servers.
Why it matters: Organizations running SmarterMail must immediately upgrade to Build 9511 or later and implement network isolation around mail servers to block the attack chain from initial access through ransomware staging, as Storm-2603 is actively exploiting these vulnerabilities in production environments.
- Source published
- First seen by Cybersecurity Tracker