Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
ransomware-group-operationactively-exploited-vulnerabilitygovernment-vulnerability-catalogidentity-authentication-vulnerability

SmarterTools Breach via Unpatched SmarterMail Server Leading to Warlock Ransomware Attempt

Updated 3mo agoFirst seen Feb 9, 20266 sources

SmarterTools confirmed it was breached after attackers exploited an unpatched instance of its SmarterMail email server inside the company’s environment. COO Derek Curtis said the intrusion occurred on January 29, 2026, when an employee-created VM running SmarterMail was not being updated; attackers used it as an entry point, then moved laterally across roughly 30 SmarterMail servers/VMs spanning the office network and a datacenter used for quality-control labs. The incident disrupted the company’s Portal support center, but SmarterTools said segmentation limited broader impact and that security tooling blocked the ransomware encryption attempt.

Reporting attributes the activity to the Warlock ransomware operation (also linked in some tracking to Gold Salem). SmarterTools did not publicly name the exploited flaw, but coverage points to CVE-2026-24423—a SmarterMail authentication bypass that can enable admin password resets—as the most likely initial vector; it was disclosed by watchTowr Labs, patched on January 15, and later added to CISA KEV with an “Exploited in ransomware attacks” designation. SmarterTools stated that only a subset of Windows systems appeared impacted (with Linux servers unaffected), and that business applications/account data were not compromised; post-incident actions included removing Windows from networks, discontinuing Active Directory, restoring some systems from recent backups, and rotating passwords.

Share:
SmarterTools Breach via Unpatched SmarterMail Server Leading to Warlock Ransomware Attempt
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

7 events from the most recent confirmed update back to the earliest known activity.

7 EVENTS
Feb 9, 20265mo ago

SmarterTools discloses the breach and begins post-incident hardening

SmarterTools publicly confirmed the January 29 breach, said some customers were affected, and urged users to update SmarterMail and review indicators of compromise. The company also reset passwords, reduced Windows usage, stopped using Active Directory, and restructured network segmentation after the incident.

Feb 6, 20265mo ago

CISA adds CVE-2026-24423 to the KEV catalog

CISA added CVE-2026-24423 to its Known Exploited Vulnerabilities catalog and flagged it as exploited in ransomware attacks. This elevated concern around SmarterMail exploitation and was cited in coverage of the SmarterTools breach.

Feb 5, 20265mo ago

Warlock ransomware attempt is contained and systems are restored

When the attackers moved toward ransomware actions, security controls including SentinelOne reportedly blocked encryption on reachable systems. SmarterTools isolated networks, shut down or disconnected servers, restored some systems from recent backups, and limited the impact to a subset of Windows infrastructure and support services.

Jan 29, 20265mo ago

Intruders move laterally across SmarterTools Windows environment

After initial access, the attackers spent several days expanding through SmarterTools' office network and quality-control data center, abusing Active Directory and deploying additional tooling such as Velociraptor and other Windows-focused utilities. Reports say about 12 Windows servers were compromised, while Linux systems were not affected.

Attackers breach SmarterTools through an unpatched SmarterMail VM

On January 29, attackers gained initial access to SmarterTools by exploiting an outdated, untracked SmarterMail virtual machine that had not been receiving updates. SmarterTools attributed the intrusion to the Warlock ransomware group, also tracked as Gold Salem and Storm-2603.

Jan 28, 20265mo ago

Mass exploitation of CVE-2026-24423 begins

watchTowr reported widespread exploitation attempts against CVE-2026-24423 starting January 28, with more than 1,000 attempts observed from roughly 60 IP addresses. The activity indicated active targeting of vulnerable SmarterMail systems before SmarterTools disclosed its own breach.

Jan 15, 20265mo ago

SmarterMail flaws CVE-2026-23760 and CVE-2026-24423 are patched

SmarterTools released SmarterMail build 9511 to fix two critical vulnerabilities: CVE-2026-23760, an authentication bypass enabling admin password resets, and CVE-2026-24423, a flaw later described as actively exploited. Multiple reports cite January 15, 2026 as the patch date.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

90 LINKEDOpen in app
Affected products
23 linked
SmartermailWindows ServerActive DirectorySmartertrackLinuxLinuxLinuxVirustotalSharepoint ServerSignalVeeam Backup & ReplicationNotepad++Vmware EsxiDocusignDropbox SignVelociraptorBingTiktokPaypalVelociraptorWinrarWinrarVelociraptor
Organizations
50 linked
SmartertoolsReliaQuestWatchTowrSupabaseMicrosoft CorporationSentinelOneNotepad++Hugging FaceCisco SystemsSocketCovewareTata MotorsQihoo 360ZscalerBI.ZONEEsetVirustotalInternational Business MachinesJaguar Land RoverSquareXeSentireHalcyonAnthropicDropboxS2WTP-LinkDocuSignKaseyaSolarWindsFortinetIvantiTrail of BitsVeeam SoftwareNetskopeSnykApplePayPalPraetorianSimpleHelpSophosBitdefenderTinesFlickrGuardsquareGoogleBithumbSaner patch managementClawHubBridgePay Network SolutionsVerimatrix
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.