Credential Theft
- Mimikatz
- Veeam-Get-Creds
Warlock is a Windows ransomware operation active since at least March 2025 and associated with the threat cluster tracked as GOLD SALEM by Sophos and Storm-2603 by Microsoft.
Profile source: Mallory opens in a new tabWarlock
Warlock is a Windows ransomware operation active since at least March 2025 and associated with the threat cluster tracked as GOLD SALEM by Sophos and Storm-2603 by Microsoft. It is also referred to as X2anylock because earlier payloads appended that extension to encrypted files. Warlock appears to be based on the leaked LockBit 3.0 builder and conducts double-extortion operations, encrypting victim systems while exfiltrating selected data for publication through a dedicated leak site. Victims have included government, technology, manufacturing, financial-services, education, critical-infrastructure, and commercial organizations across North America, Europe, Asia, Africa, and South America.
Operators have repeatedly obtained access by exploiting unpatched, internet-facing on-premises Microsoft SharePoint Server vulnerabilities, notably the ToolShell chain, and have also been linked to exploitation of exposed Veeam Backup & Replication and other enterprise applications. Post-compromise activity includes deployment of web shells and remote-access tooling, Active Directory and host reconnaissance, credential theft from LSASS and Windows credential stores, credential replication, creation or modification of privileged accounts, and lateral movement through SMB administrative shares, PsExec, Impacket, PowerShell Remoting, RDP, and remote-management software. Ransomware payloads have been distributed domain-wide using Active Directory Group Policy Objects and startup scripts.
Warlock operators use multiple command-and-control and persistence channels, including abused Velociraptor, Cloudflare Tunnel, Visual Studio Code tunnels, web shells, reverse proxies, and remote-management products. They evade defenses by terminating security processes, including through Bring Your Own Vulnerable Driver techniques using signed vulnerable drivers, and have also used DLL sideloading. Data theft has been performed with renamed Rclone instances to attacker-controlled cloud storage. Microsoft assesses Storm-2603 as China-based with moderate confidence; other researchers have not independently confirmed that attribution.
da8de7257c6897d2220cdf9d4755b15aeb38715807e3665716d2ee761c266fdb3DCE1C43491FC92EA7010322040B254FDD2731001C2DDC2B9E819F0C946BDC3CD251FA3B694A84490152E99B9EC4BCFE16080AFCFD6FDCD87512027E85DB318F7B3440982637FC2847F71685F79A71AD8BB2E3E7EDFC38970FDC05E922E429B5DFC325C7D0E91F216DE8F3537C1A1C97F197Reported operators
The ransomware encrypted files, appending the extension .x2anylock to each encrypted file (hence Warlock’s alternative naming scheme “X2anylock”).
Warlock operators exploited vulnerable Microsoft SharePoint servers, maintained multiple C2 channels, disabled security tooling through BYOVD, exfiltrated data with renamed Rclone, and deployed encryption payloads via Active Directory GPO.
そのうちの一つ(Microsoftが「Storm-2603」と呼ぶグループ)が、Warlockと呼ばれるランサムウェアを展開したと報告されています。
Groups including UAC-0238 exploited exposed RDP services to push ransomware variants such as X2anylock, Warlock, and LockBit 3.0 into compromised environments.
Warlock Ransomware Hits US Firms Exploiting SharePoint Zero-Day, Linked to China’s CamoFei APT
GOLD SALEM (also known as Storm-2603) is a financially motivated cybercriminal threat group calling itself Warlock Group responsible for the distribution of the Warlock ransomware.
"WarLock ransomware hit Colt Telecom, causing outages in hosting, porting, Colt Online, and Voice API since August 12."
"Storm-2603 was using the exploit to deploy Warlock and another ransomware payload, LockBit."
"Storm-2603 was using the exploit to deploy Warlock and another ransomware payload, LockBit."
"Storm-2603 was using the exploit to deploy Warlock and another ransomware payload, LockBit."
"Storm-2603 was using the exploit to deploy Warlock and another ransomware payload, LockBit."
"Storm-2603 was using the exploit to deploy Warlock and another ransomware payload, LockBit."
Exploited software
MITRE ATT&CK
Reporting
CISA and Microsoft warned that multiple on-premises SharePoint Server vulnerabilities are being actively exploited against internet-facing systems, with attackers using a chain involving CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164 to gain unauthorized access, execute code, steal IIS and ASP.NET machine keys, maintain persistence, and deploy malware. The agencies said the activity affects supported on-premises SharePoint deployments rather than SharePoint Online, and follows earlier Microsoft reporting that Chinese threat actors including Linen Typhoon, Violet Typhoon, and Storm-2603 had abused similar SharePoint flaws to install web shells, dump credentials, move laterally, and in some cases deploy Warlock ransomware. Microsoft’s July 2026 updates also fixed two additional critical SharePoint bugs, CVE-2026-55040 and CVE-2026-58644, which were not yet confirmed as exploited but were assessed as likely targets for rapid weaponization, while separate reporting said another SharePoint exploit chain may remain unpatched pending a later release. Defenders were urged to immediately apply available patches, enable AMSI in Full Mode, reduce or remove internet exposure, restrict access to SharePoint Central Administration, review logs and endpoint telemetry for compromise, and only rotate IIS or ASP.NET machine keys after confirming whether intrusion activity is already present.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.