Skip Navigation
Get a Demo
 
 
 
 
 
 
 
 
 
Resources Videos
Security operations

Red Canary Office Hours: Episode 40 – The hidden tunnels of STORM-2603’s ransomware ops

Air Date: November 4, 2025

The hidden tunnels of STORM-2603’s ransomware ops

Dave and Keith are joined by Principal Security Researcher Phil Hagen to peel back the layers of STORM-2603, a suspected China-based threat actor group and how it leverages legitimate tools to lead to tunneling malicious traffic and ransomware deployment.

Phil discusses how adversaries’ use of DFIR-focused tools can complicate detection opportunities and how organizations can mitigate risks through auditing and blocklists.

View the video
Red Canary Office Hours: Episode 39 – Nightmare on supply chain street
Red Canary Office Hours: Episode 39 – Nightmare on supply chain street
Red Canary Office Hours: Episode 38 – September’s top threats, featuring Stef Rand from our Intelligence team!
Red Canary Office Hours: Episode 38 – September’s top threats, featuring Stef Rand from our Intelligence team!
Red Canary Office Hours: Episode 37 – A beginner’s guide to threat hunting
Red Canary Office Hours: Episode 37 – A beginner’s guide to threat hunting
Red Canary Office Hours: Episode 36 – Building AI agents for SecOps
Red Canary Office Hours: Episode 36 – Building AI agents for SecOps

Security gaps? We got you.

Sign up for our monthly email newsletter for expert insights on MDR, threat intel, and security ops—straight to your inbox.


 
 
Back to Top