← Threat Actors / China / Storm-2603
DOSSIER // STORM-2603

Storm-2603

▲ High Threat China
Primary Aliases: APT31 JUDGMENT PANDA Violet Typhoon Altaire
Sponsor / State Affiliation Independent / Not Attributed
Primary Motivation Espionage / Financial
Active Timeline Unknown – Present
Confidence Rating 70% (Grounded)

The group Microsoft tracks as Storm-2603 is assessed with medium confidence to be a China-based threat actor. Microsoft has not identified links between Storm-2603 and other known Chinese threat actors. Microsoft tracks this threat actor in association with attempts to steal MachineKeys via the on-premises SharePoint vulnerabilities. Although Microsoft has observed this threat actor deploying Warlock and Lockbit ransomware in the past, Microsoft is currently unable to confidently assess the threat actor’s objectives. Additional actors may use these exploits to target unpatched on-premises SharePoint systems, further emphasizing the need for organizations to implement mitigations and security updates immediately.

⚔️ Weaponized CVE Matrix (0)

No specific weaponized CVEs currently mapped in the public baseline.

🎯 Target Sectors & Focus

Defense & Aerospace Government & Diplomacy Financial & Crypto Critical Infrastructure

🛡️ MITRE ATT&CK® Attack Lifecycle (6 TTPs)

📥 Download Navigator JSON
Copied to clipboard

LINK COPIED TO CLIPBOARD