Skip to content

Warlock

Warlock is a ransomware family active since at least March 2025 and publicly advertised from June 2025.

Profile source: Mallory opens in a new tab

Warlock

Family profile

Warlock is a ransomware family active since at least March 2025 and publicly advertised from June 2025. It has been associated with the threat cluster tracked as Storm-2603 by Microsoft and GOLD SALEM by Sophos. Multiple investigations link Warlock activity to exploitation of internet-facing enterprise software, especially on-premises Microsoft SharePoint through the ToolShell vulnerability chain, and also to compromises involving other exposed applications. Observed victims span government, healthcare, manufacturing, telecommunications, agriculture, energy and natural resources, and other commercial sectors across North America, Europe, South America, Latin America, and Asia-Pacific.

Warlock intrusions commonly involve exploitation of public-facing applications for initial access, followed by deployment of web shells or other remote-access tooling, credential theft, lateral movement, defense evasion, data exfiltration, and ransomware deployment. Reported post-compromise tradecraft includes theft of credentials from LSASS, use of PsExec, Impacket, WMI, RDP, WinRM, and Group Policy Objects for propagation and payload distribution. Operators have also used legitimate or dual-use remote management and incident-response tools such as Zoho Assist and Velociraptor to maintain access and blend into administrative activity.

Defense evasion is a notable feature of Warlock operations. Observed campaigns used Bring Your Own Vulnerable Driver techniques to tamper with or terminate endpoint security products, and some reporting also describes DLL sideloading chains used to load vulnerable signed drivers for broad endpoint-agent disruption. Persistence mechanisms seen in Warlock-linked intrusions include web shells, scheduled tasks, remote management agents, and tunneling or remote-access channels established through administrative tooling.

Warlock is also tied to double-extortion style operations. Victim organizations have been listed on a leak site, and reporting links some intrusions both to ransomware deployment and to data theft followed by publication or sale claims. The group’s operational model appears compatible with extortion-focused ransomware activity rather than encryption alone.

Microsoft has assessed Storm-2603 with moderate confidence as China-based, but that attribution has not been universally corroborated. What is well supported is the repeated association between Storm-2603/GOLD SALEM and Warlock deployments, particularly in attacks exploiting on-premises SharePoint vulnerabilities and using GPO-based ransomware rollout inside compromised Windows environments.

Capabilities

  • Byovd
  • Credential Theft
  • Defense Evasion
  • Dll Sideloading
  • Exfiltration
  • Extortion
  • Initial Access
  • Lateral Movement
  • Persistence
  • Privilege Escalation
  • Reconnaissance

Operational record

4
Indicators
1
YARA rules
2
Ransom notes
4
Leak sites
1 available

Credential Theft

  • Mimikatz
  • Veeam-Get-Creds

Defense Evasion

  • Antiy System In-Depth Analysis Toolkit driver (BYOVD)
  • NsecSoft driver (BYOVD)
  • Rising Antivirus driver (BYOVD)
  • VMTools AV Killer (BYOVD)

Discovery Enum

  • Everything.exe
  • SecurityCheck

Exfiltration

  • RClone

LOLBAS

  • Minidump
  • Msiexec
  • PowerShell Remoting (PSRemoting)
  • PsExec
  • RDP Patcher

Networking

  • Azure Blog Storage
  • Catbox[.]moe
  • Cloudflared
  • MinIO
  • OpenSSH
  • Supabase
  • VS Code Tunnel
  • Yuze

Offsec

  • Cobalt Strike
  • Velociraptor

RMM Tools

  • Radmin
  • TightVNC

Published indicators

Sha256

1 total
  • da8de7257c6897d2220cdf9d4755b15aeb38715807e3665716d2ee761c266fdb

Tox

3 total
  • 3DCE1C43491FC92EA7010322040B254FDD2731001C2DDC2B9E819F0C946BDC3CD251FA3B694A
  • 84490152E99B9EC4BCFE16080AFCFD6FDCD87512027E85DB318F7B3440982637FC2847F71685
  • F79A71AD8BB2E3E7EDFC38970FDC05E922E429B5DFC325C7D0E91F216DE8F3537C1A1C97F197

Reported operators

Threat actors

10 named in public reporting
Storm-2603

Talos IR responded to Sinobi ransomware for the first time, as well as previously seen variants Nitrogen and Warlock... In one engagement, we observed Warlock ransomware operators (also known as Storm-2603) deploying an installer for the RMM tool Zoho Assist Unattended Agent.

UAC-0238

Groups including UAC-0238 exploited exposed RDP services to push ransomware variants such as X2anylock, Warlock, and LockBit 3.0 into compromised environments.

camofei

Warlock Ransomware Hits US Firms Exploiting SharePoint Zero-Day, Linked to China’s CamoFei APT

Warlock

GOLD SALEM (also known as Storm-2603) is a financially motivated cybercriminal threat group calling itself Warlock Group responsible for the distribution of the Warlock ransomware.

cnkjasdfgd

"WarLock ransomware hit Colt Telecom, causing outages in hosting, porting, Colt Online, and Voice API since August 12."

ZIRCONIUM

"Storm-2603 was using the exploit to deploy Warlock and another ransomware payload, LockBit."

Chamelgang

"Storm-2603 was using the exploit to deploy Warlock and another ransomware payload, LockBit."

Threat Group-3390

"Storm-2603 was using the exploit to deploy Warlock and another ransomware payload, LockBit."

Sheathminer

"Storm-2603 was using the exploit to deploy Warlock and another ransomware payload, LockBit."

Budworm

"Storm-2603 was using the exploit to deploy Warlock and another ransomware payload, LockBit."

Exploited software

Vulnerabilities linked to Warlock

13 CVEs

MITRE ATT&CK

Warlock in ATT&CK

5 distinct techniques

Reporting

Research mentioning Warlock

Jul 20
Cyber Security News

Microsoft SharePoint Vulnerabilities Actively Exploited for RCE, Web Shells, and IIS Key Theft

CISA and Microsoft warned that multiple on-premises SharePoint Server vulnerabilities are being actively exploited against internet-facing systems, with attackers using a chain involving CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164 to gain unauthorized access, execute code, steal IIS and ASP.NET machine keys, maintain persistence, and deploy malware. The agencies said the activity affects supported on-premises SharePoint deployments rather than SharePoint Online, and follows earlier Microsoft reporting that Chinese threat actors including Linen Typhoon, Violet Typhoon, and Storm-2603 had abused similar SharePoint flaws to install web shells, dump credentials, move laterally, and in some cases deploy Warlock ransomware. Microsoft’s July 2026 updates also fixed two additional critical SharePoint bugs, CVE-2026-55040 and CVE-2026-58644, which were not yet confirmed as exploited but were assessed as likely targets for rapid weaponization, while separate reporting said another SharePoint exploit chain may remain unpatched pending a later release. Defenders were urged to immediately apply available patches, enable AMSI in Full Mode, reduce or remove internet exposure, restrict access to SharePoint Central Administration, review logs and endpoint telemetry for compromise, and only rotate IIS or ASP.NET machine keys after confirming whether intrusion activity is already present.

Jul 20
Truesec

Microsoft SharePoint Server Vulnerabilities Actively Exploited - Truesec

Jul 20
Cyberveille

CISA alerte sur des vulnérabilités SharePoint activement exploitées et exige un patch immédiat | CyberVeille

Jul 18
Resecurity

Resecurity | From Web Request to Domain Compromise: Understanding the July 2026 SharePoint Attacks

Jul 15
Scworld

CISA warns that three SharePoint Server bugs are actively exploited | news | SC Media

Jul 15
Malware News

AL26-017 - Critical vulnerabilities impacting Microsoft SharePoint Server - CVE-2026-56164, CVE-2026-55040 and CVE-2026-58644 - Malware News - Malware Analysis, News and Indicators

Jul 15
Security Online Info

CISA: 3 SharePoint Vulnerabilities Exploited in the Wild

Jul 15
Register Security

CISA sounds alarm over trio of exploited SharePoint flaws

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.