INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
SmarterTools Network Breached via Software Flaw
| 2026-02-09 19:08 CRITICAL LOW DATA BREACH VULNERABILITY DISCLOSURE
Executive Summary
AI-generated
The Warlock ransomware gang breached SmarterTools' network on January 29, 2026, after compromising an email system via a single virtual machine set up by an employee. The attackers exploited the CVE-2026-23760 authentication bypass flaw in SmarterMail before Build 9518 to gain access and then moved laterally using Windows-centric tooling and persistence methods. Twelve Windows servers on SmarterTools' office network, as well as a secondary data center, were compromised, but customer account data was not directly impacted. The attackers waited roughly a week after gaining initial access, encrypting all reachable machines before being stopped by Sentinel One security products. This attack is linked to Storm-2603, a Chinese nation-state actor tracked by Halcyon cybersecurity company and confirmed by ReliaQuest with moderate-to-high confidence.
Technical Mitigations AI-generated
• Upgrade to SmarterMail Build 9511 or later to address CVE-2026-23760 and CVE-2026-24423 vulnerabilities.
• Monitor for probes related to CVE-2026-24423, another SmarterMail flaw actively exploited by ransomware actors.
• Use Sentinel One security products to detect and prevent the final payload from performing encryption in case of a successful attack.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-23760CVE-2026-23760
CVE-2026-24423CVE-2026-24423
Target & Sectors
CN
Incident Timeline
October 2025
Threat actors exploited a flaw in SmarterMail's software, CVE-2026-23760, to gain initial access before using Velociraptor and other tools to maintain their position.
Click on any entity below to view its context and source!
infrastructure
Smartermail
ReliaQuest also saw probes for CVE-2026-24423, another SmarterMail flaw
flagged by CISA
as actively exploited by ransomware actors last week, although the primary vector was CVE-2026-23760.
To address all recent flaws in the SmarterMail product, administrators are recommended to
upgrade to Build 9511 or later
as soon as possible.
2026/02/09
The Warlock ransomware gang breached SmarterTools' network via a compromised email system using an authentication bypass flaw in SmarterMail before Build 9518, specifically CVE-2026-23760.
Click on any entity below to view its context and source!
infrastructure
Smartermail
The vulnerability exploited in the attack to gain access is
CVE-2026-23760
, an authentication bypass flaw in SmarterMail before Build 9518, which allows resetting administrator passwords and obtaining full privileges.
The company's Chief Commercial Officer, Derek Curtis, says that the intrusion occurred on January 29, via a single SmarterMail virtual machine (VM) set up by an employee.
"Prior to the breach, we had approximately 30 servers/VMs with SmarterMail installed throughout our network,"
Curtis explained
.
infrastructure
30 servers
"Prior to the breach, we had approximately 30 servers/VMs with SmarterMail installed throughout our network,"
Curtis explained
.
infrastructure
Windows
Although SmarterTools assures that customer data wasn’t directly impacted by this breach, 12 Windows servers on the company’s office network, as well as a secondary data center used for laboratory tests, quality control, and hosting, were confirmed…
The attackers moved laterally from that one vulnerable VM via Active Directory, using Windows-centric tooling and persistence methods.
infrastructure
12 Windows servers
Although SmarterTools assures that customer data wasn’t directly impacted by this breach, 12 Windows servers on the company’s office network, as well as a secondary data center used for laboratory tests, quality control, and hosting, were confirmed…
infrastructure
Linux
Linux servers, which constitute the majority of the company’s infrastructure, were not compromised by this attack.
infrastructure
Winrar
Tools used in the attacks include Velociraptor, SimpleHelp, and vulnerable versions of WinRAR, while startup items and scheduled tasks were also used for persistence, according to the company.
Tactical Metrics
Metrics
infrastructure
Smartermail
Affected Product
Click for context!
ReliaQuest also saw probes for CVE-2026-24423, another SmarterMail flaw
flagged by CISA
as actively exploited by ransomware actors last week, although the primary vector was CVE-2026-23760.
The company's Chief Commercial Officer, Derek Curtis, says that the intrusion occurred on January 29, via a single SmarterMail virtual machine (VM) set up by an employee.
"Prior to the breach, we had approximately 30 servers/VMs with SmarterMail installed throughout our network,"
Curtis explained
.
The vulnerability exploited in the attack to gain access is
CVE-2026-23760
, an authentication bypass flaw in SmarterMail before Build 9518, which allows resetting administrator passwords and obtaining full privileges.
To address all recent flaws in the SmarterMail product, administrators are recommended to
upgrade to Build 9511 or later
as soon as possible.
Metrics
infrastructure
30
Servers
"Prior to the breach, we had approximately 30 servers/VMs with SmarterMail installed throughout our network,"
Curtis explained
.
Metrics
infrastructure
Windows
Affected Product
Although SmarterTools assures that customer data wasn’t directly impacted by this breach, 12 Windows servers on the company’s office network, as well as a secondary data center used for laboratory tests, quality control, and hosting, were confirmed…
The attackers moved laterally from that one vulnerable VM via Active Directory, using Windows-centric tooling and persistence methods.
Metrics
infrastructure
12
Windows Servers
Although SmarterTools assures that customer data wasn’t directly impacted by this breach, 12 Windows servers on the company’s office network, as well as a secondary data center used for laboratory tests, quality control, and hosting, were confirmed…
Metrics
infrastructure
Linux
Affected Product
Linux servers, which constitute the majority of the company’s infrastructure, were not compromised by this attack.
Metrics
infrastructure
Winrar
Affected Product
Tools used in the attacks include Velociraptor, SimpleHelp, and vulnerable versions of WinRAR, while startup items and scheduled tasks were also used for persistence, according to the company.
Intelligence Sources
BleepingComputer
2026-02-09
Hackers breach SmarterTools network using flaw in its own software
BleepingComputer
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-07T08:49
Comprehensive Tactical Telemetry
Highly Correlated Entities
13x
organisation
Identified Entity
Halcyon
entity
4x
timeline
Temporal Reference
2026-02-02
date
4x
infrastructure
Affected Product
Smartermail
software
2x
tactic
Cyber Operation Type
Ransomware
tactic
2x
vulnerability
Exploited CVE
CVE-2026-24423
cve
Contextual Telemetry
Context Block
4 METRICS
target region
Target Country
China
country
attribution
Attributing Entity
CISA
authority
infrastructure
Servers
30
servers
infrastructure
Windows Servers
12
windows servers
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.