AK47 C2
-
Storm-2603 Exploits SharePoint Vulnerabilities to Deploy Ransomware
A recent analysis reveals that Storm-2603, a suspected China-based threat actor, is exploiting Microsoft SharePoint vulnerabilities using a bespoke command-and-control framework, deploying ransomware like Warlock and LockBit.