Inside the Cyberstorm: China-Linked Hacker Group Unleashes AK47 C2 on Microsoft SharePoint

Listen to this Post

Featured Image
Growing Cyber Threats in 2025: A New Wave of Sophisticated Attacks

A newly identified cyber threat campaign, tied to a group called Storm-2603, is targeting organizations worldwide by exploiting Microsoft SharePoint Server vulnerabilities. Leveraging a powerful custom command-and-control system known as AK47 C2, this group has demonstrated advanced techniques, including sideloading malware, abusing legitimate tools, and deploying multiple ransomware strains in a single campaign. As the cybersecurity world scrambles to contain these attacks, the incident sheds light on the increasingly blurred line between state-sponsored espionage and financially motivated cybercrime.

💥 Storm-2603: The Full Scope of the Operation

Cybersecurity firm Check Point Research has revealed that Storm-2603—a threat actor suspected to be based in China—has adopted a tailored C2 (command-and-control) infrastructure named AK47 C2. This framework operates through two primary clients: AK47HTTP and AK47DNS, capable of executing remote commands via HTTP or DNS protocols.

The group’s attack exploits two recent Microsoft SharePoint vulnerabilities—CVE-2025-49706 and CVE-2025-49704, also known as ToolShell. These flaws have been weaponized to drop Warlock ransomware (also known as X2anylock). Interestingly, Storm-2603 isn’t limiting itself to just one malware family. They’ve been deploying LockBit Black alongside Warlock—an unusual behavior rarely seen among established cybercrime syndicates.

Check Point’s investigation indicates that the group has been active since at least March 2025, with confirmed attacks in both Latin America and APAC regions. Tools in use range from open-source scanners like masscan, and Windows utilities such as WinPcap, PsExec, and SharpHostInfo, to a custom DNS backdoor named dnsclient.exe. This malware connects to a spoofed domain (update.updatemicfosoft[.]com) that mimics Microsoft’s official domains.

This backdoor is fully integrated into the AK47 C2 suite and is capable of gathering host data, executing server commands, and operating stealthily under Windows environments using cmd.exe. Notably, Microsoft also flagged this same infrastructure in conjunction with a malicious web shell titled “spinstall0.aspx”, further confirming the group’s consistent targeting methodology.

Payload delivery mechanisms used by Storm-2603 include:

7-Zip binaries (`7z.exe` and `7z.dll`) to sideload Warlock ransomware

Installer bbb.msi, which triggers LockBit Black deployment

A specialized MSI, discovered in April 2025, that launches both ransomware strains and drops an antivirus killer executable (VMToolsEng.exe). This executable uses a BYOVD (Bring Your Own Vulnerable Driver) technique involving ServiceMouse.sys, a driver from Antiy Labs, to disable endpoint security.

At this stage, Storm-2603’s underlying motives remain ambiguous. While profit from ransomware is evident, the group’s use of espionage-style methods, such as BYOVD and sophisticated DLL sideloading, hints at nation-state affiliations. Such behavior aligns with known Chinese, Iranian, and North Korean tactics that straddle both spying and profit-driven goals.

💡 What Undercode Say:

Hybrid Warfare: Ransomware Meets Espionage

Storm-2603’s tactics represent a dangerous convergence of advanced persistent threat (APT) methodology with traditional cybercrime. The use of the AK47 C2 framework suggests careful premeditation and resource investment, typically seen in state-sponsored attacks. The naming (AK47) itself may symbolize an aggressive, “no-holds-barred” approach to cyber warfare.

Their use of sideloading legitimate software like 7-Zip and clink_x86.exe demonstrates a deep understanding of how to bypass endpoint detection. It’s also worth noting how cleverly they spoof legitimate-looking domains to avoid immediate red flags. For example, update.updatemicfosoft[.]com could fool untrained eyes into thinking it’s a Microsoft service.

From a defensive perspective, organizations relying solely on antivirus or EDR solutions are at risk. The BYOVD method—leveraging ServiceMouse.sys—effectively disables security defenses before the ransomware strikes, removing the last layer of protection.

Storm-2603’s dual ransomware deployment tactic is particularly notable. Running both LockBit Black and Warlock increases the chances of a successful extortion. It’s a sign that the attackers are optimizing their operations not just for damage, but for profit.

The APAC and Latin American targeting shows strategic intent: these are regions often under-resourced in cybersecurity, making them vulnerable. Yet the use of English-based spoofed domains implies that the group may also expand toward Western enterprises.

More broadly, this attack highlights how the lines between state-sponsored actors and cybercriminals are vanishing. Groups like Storm-2603 operate with military-grade precision while deploying tools for financial gain—making attribution and defense even harder.

Defenders must now treat every advanced intrusion as a potential hybrid threat, possibly motivated by both data theft and extortion. With AK47 C2 in play, the bar for sophistication has been raised.

✅ Fact Checker Results:

Storm-2603 is a real, Microsoft-tracked threat actor suspected to be China-based.
The CVEs exploited in this campaign are verified and recently disclosed.
Dual deployment of ransomware families, including LockBit Black and Warlock, is confirmed by Check Point data.

🔮 Prediction:

Storm-2603’s tactics signal a new era of “blended cyber threats”, where espionage, sabotage, and financial extortion converge. As AK47 C2 becomes more widespread, similar frameworks may be adopted by other nation-aligned threat actors. Expect to see more multi-ransomware attacks, weaponized DLL sideloading, and BYOVD techniques in future campaigns—especially targeting under-protected regions and cloud-hosted environments.

🕵️‍📝✔️Let’s dive deep and fact‑check.

References:

Reported By: thehackernews.com
Extra Source Hub:
https://www.instagram.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon