HomeSecurityWarlock Ransomware breached SmarterTools

Warlock Ransomware breached SmarterTools

SmarterTools confirmed last week that the Warlock ransomware group (also known as Storm-2603) had breached its network, exploiting an unpatched version of SmarterMail.

Warlock Ransomware SmarterTools

The company's Commercial Director, Derek Curtis, said the incident occurred on January 29, 2026, when a mail server that had not been updated to the latest version was compromised.

Warlock Ransomware: Attack on SmarterTools

“ Prior to the breach, we had approximately 30 servers/virtual machines with SmarterMail installed across our network ,” Curtis explained . “ Unfortunately, we were unaware of a VM that had been configured by an employee and had not been updated. As a result, that server was compromised, leading to a broader breach .”

However, SmarterTools stressed that the breach did not affect its website, shopping cart, My Account portal , and several other services. Also, no business applications or account data were affected or compromised.

See also: Dutch authorities confirm Ivanti zero-day exploit

About 12 Windows servers in the company's office network, as well as a secondary data center used for quality control (QC) testing, were confirmed to be affected. According to its CEO, Tim Uzzanti, the "ransomware attack attempt" also affected hosted customers using SmarterTrack.

“ Hosted customers using SmarterTrack were the ones most impacted ,” Uzzanti said . “ This was not due to any issue within SmarterTrack, but rather that this environment was more easily accessible than others once our network was breached .”

Additionally, SmarterTools identified that the Warlock group waited a few days after the initial access to take control of the Active Directory server and create new users. This was followed by the installation of additional payloads such as Velociraptor and the file encryption locker .

Warlock Ransomware breached SmarterTools

“Once these malicious actors gain access, they typically install files and wait about 6-7 days before taking further action,” Curtis said. “This explains why some customers experienced a breach even after the update – the initial breach occurred before the update, but the malicious activity was activated later.”

See also: Hackers exploit SolarWinds WHD vulnerabilities

SmarterMail vulnerabilities

It is currently unclear which SmarterMail vulnerability the attackers exploited, but it is worth noting that multiple security holes in the email software have been actively exploited:

  • CVE-2025-52691 (CVSS score: 10.0)
  • CVE-2026-23760 (CVSS score: 9.3)
  • CVE-2026-24423 (CVSS scores: 9.3)

CVE-2026-23760 is an authentication bypassthat could allow any user to reset the administrator password of the SmarterMail system by sending a specially crafted HTTP request.

CVE-2026-24423, on the other hand, exploits a weakness in the ConnectToHub API method to achieve unauthorized remote code execution (RCE).

The vulnerabilities were addressed by SmarterTools in version 9511.

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: Bloody Wolf targets Uzbekistan and Russia with NetSupport RAT

Last week, the U.S. Cybersecurity and Infrastructure Security Administration (CISA) confirmed that CVE-2026-24423 was being used in ransomware.

Warlock Ransomware breached SmarterTools

In a report published on Monday, cybersecurity firm ReliaQuest said it had detected activity, linked to Warlock, that involved the abuse of CVE-2026-23760.

“While this vulnerability allows attackers to bypass authentication and reset administrator passwords, Storm-2603 combines this access with the software’s ‘Volume Mount’ feature to gain complete control of the system,” said security researcher Alexa Feminella. “Upon entry, the group installs Velociraptor, a legitimate digital forensics it has used in previous campaigns, to maintain access and prepare the ground for ransomware.”

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS