Storm-2603 Hackers Deploy Ransomware on Unpatched SharePoint Systems
Microsoft's SharePoint platform has been targeted by hackers in recent attacks, with threat actors exploiting vulnerabilities to gain unauthorized access and deploy ransomware. The attackers, known as Storm-2603, have used publicly known weaknesses in on-premises SharePoint servers to infiltrate internal file systems and steal sensitive data.
The company has issued multiple security patches to address the affected vulnerabilities, but despite these efforts, Storm-2603 has continued to deploy ransomware on unpatched systems. Warlock ransomware, which was first detected in June 2025, is being used by the attackers to encrypt files and demand payment from victims.
Microsoft recommends installing the latest security patches, using strong passwords, and continuously monitoring SharePoint servers for any signs of suspicious activity. The company also advises using tools within Microsoft Defender, such as Vulnerability Management and External Attack Surface Management.