Skip to content

Warlock

Warlock is a Windows ransomware operation active since at least March 2025 and associated with the threat cluster tracked as GOLD SALEM by Sophos and Storm-2603 by Microsoft.

Profile source: Mallory opens in a new tab

Warlock

Family profile

Warlock is a Windows ransomware operation active since at least March 2025 and associated with the threat cluster tracked as GOLD SALEM by Sophos and Storm-2603 by Microsoft. It is also referred to as X2anylock because earlier payloads appended that extension to encrypted files. Warlock appears to be based on the leaked LockBit 3.0 builder and conducts double-extortion operations, encrypting victim systems while exfiltrating selected data for publication through a dedicated leak site. Victims have included government, technology, manufacturing, financial-services, education, critical-infrastructure, and commercial organizations across North America, Europe, Asia, Africa, and South America.

Operators have repeatedly obtained access by exploiting unpatched, internet-facing on-premises Microsoft SharePoint Server vulnerabilities, notably the ToolShell chain, and have also been linked to exploitation of exposed Veeam Backup & Replication and other enterprise applications. Post-compromise activity includes deployment of web shells and remote-access tooling, Active Directory and host reconnaissance, credential theft from LSASS and Windows credential stores, credential replication, creation or modification of privileged accounts, and lateral movement through SMB administrative shares, PsExec, Impacket, PowerShell Remoting, RDP, and remote-management software. Ransomware payloads have been distributed domain-wide using Active Directory Group Policy Objects and startup scripts.

Warlock operators use multiple command-and-control and persistence channels, including abused Velociraptor, Cloudflare Tunnel, Visual Studio Code tunnels, web shells, reverse proxies, and remote-management products. They evade defenses by terminating security processes, including through Bring Your Own Vulnerable Driver techniques using signed vulnerable drivers, and have also used DLL sideloading. Data theft has been performed with renamed Rclone instances to attacker-controlled cloud storage. Microsoft assesses Storm-2603 as China-based with moderate confidence; other researchers have not independently confirmed that attribution.

Capabilities

  • Byovd
  • Credential Theft
  • Defense Evasion
  • Dll Sideloading
  • Exfiltration
  • Initial Access
  • Lateral Movement
  • Persistence
  • Post Exploitation
  • Privilege Escalation
  • Reconnaissance

Operational record

4
Indicators
1
YARA rules
2
Ransom notes
4
Leak sites
0 available

Credential Theft

  • Mimikatz
  • Veeam-Get-Creds

Defense Evasion

  • Antiy System In-Depth Analysis Toolkit driver (BYOVD)
  • NsecSoft driver (BYOVD)
  • Rising Antivirus driver (BYOVD)
  • VMTools AV Killer (BYOVD)

Discovery Enum

  • Everything.exe
  • SecurityCheck

Exfiltration

  • RClone

LOLBAS

  • Minidump
  • Msiexec
  • PowerShell Remoting (PSRemoting)
  • PsExec
  • RDP Patcher

Networking

  • Azure Blog Storage
  • Catbox[.]moe
  • Cloudflared
  • MinIO
  • OpenSSH
  • Supabase
  • VS Code Tunnel
  • Yuze

Offsec

  • Cobalt Strike
  • Velociraptor

RMM Tools

  • Radmin
  • TightVNC

Published indicators

Sha256

1 total
  • da8de7257c6897d2220cdf9d4755b15aeb38715807e3665716d2ee761c266fdb

Tox

3 total
  • 3DCE1C43491FC92EA7010322040B254FDD2731001C2DDC2B9E819F0C946BDC3CD251FA3B694A
  • 84490152E99B9EC4BCFE16080AFCFD6FDCD87512027E85DB318F7B3440982637FC2847F71685
  • F79A71AD8BB2E3E7EDFC38970FDC05E922E429B5DFC325C7D0E91F216DE8F3537C1A1C97F197

Reported operators

Threat actors

12 named in public reporting
Storm2603

The ransomware encrypted files, appending the extension .x2anylock to each encrypted file (hence Warlock’s alternative naming scheme “X2anylock”).

Water Manaul

Warlock operators exploited vulnerable Microsoft SharePoint servers, maintained multiple C2 channels, disabled security tooling through BYOVD, exfiltrated data with renamed Rclone, and deployed encryption payloads via Active Directory GPO.

Storm-2603

そのうちの一つ(Microsoftが「Storm-2603」と呼ぶグループ)が、Warlockと呼ばれるランサムウェアを展開したと報告されています。

UAC-0238

Groups including UAC-0238 exploited exposed RDP services to push ransomware variants such as X2anylock, Warlock, and LockBit 3.0 into compromised environments.

camofei

Warlock Ransomware Hits US Firms Exploiting SharePoint Zero-Day, Linked to China’s CamoFei APT

Warlock

GOLD SALEM (also known as Storm-2603) is a financially motivated cybercriminal threat group calling itself Warlock Group responsible for the distribution of the Warlock ransomware.

cnkjasdfgd

"WarLock ransomware hit Colt Telecom, causing outages in hosting, porting, Colt Online, and Voice API since August 12."

ZIRCONIUM

"Storm-2603 was using the exploit to deploy Warlock and another ransomware payload, LockBit."

Chamelgang

"Storm-2603 was using the exploit to deploy Warlock and another ransomware payload, LockBit."

Threat Group-3390

"Storm-2603 was using the exploit to deploy Warlock and another ransomware payload, LockBit."

Sheathminer

"Storm-2603 was using the exploit to deploy Warlock and another ransomware payload, LockBit."

Budworm

"Storm-2603 was using the exploit to deploy Warlock and another ransomware payload, LockBit."

Exploited software

Vulnerabilities linked to Warlock

13 CVEs

MITRE ATT&CK

Warlock in ATT&CK

11 distinct techniques

Reporting

Research mentioning Warlock

Jul 20
Cyber Security News

Microsoft SharePoint Vulnerabilities Actively Exploited for RCE, Web Shells, and IIS Key Theft

CISA and Microsoft warned that multiple on-premises SharePoint Server vulnerabilities are being actively exploited against internet-facing systems, with attackers using a chain involving CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164 to gain unauthorized access, execute code, steal IIS and ASP.NET machine keys, maintain persistence, and deploy malware. The agencies said the activity affects supported on-premises SharePoint deployments rather than SharePoint Online, and follows earlier Microsoft reporting that Chinese threat actors including Linen Typhoon, Violet Typhoon, and Storm-2603 had abused similar SharePoint flaws to install web shells, dump credentials, move laterally, and in some cases deploy Warlock ransomware. Microsoft’s July 2026 updates also fixed two additional critical SharePoint bugs, CVE-2026-55040 and CVE-2026-58644, which were not yet confirmed as exploited but were assessed as likely targets for rapid weaponization, while separate reporting said another SharePoint exploit chain may remain unpatched pending a later release. Defenders were urged to immediately apply available patches, enable AMSI in Full Mode, reduce or remove internet exposure, restrict access to SharePoint Central Administration, review logs and endpoint telemetry for compromise, and only rotate IIS or ASP.NET machine keys after confirming whether intrusion activity is already present.

Jul 20
Truesec

Microsoft SharePoint Server Vulnerabilities Actively Exploited - Truesec

Jul 20
Cyberveille

CISA alerte sur des vulnérabilités SharePoint activement exploitées et exige un patch immédiat | CyberVeille

Jul 18
Resecurity

Resecurity | From Web Request to Domain Compromise: Understanding the July 2026 SharePoint Attacks

Jul 15
Scworld

CISA warns that three SharePoint Server bugs are actively exploited | news | SC Media

Jul 15
Malware News

AL26-017 - Critical vulnerabilities impacting Microsoft SharePoint Server - CVE-2026-56164, CVE-2026-55040 and CVE-2026-58644 - Malware News - Malware Analysis, News and Indicators

Jul 15
Security Online Info

CISA: 3 SharePoint Vulnerabilities Exploited in the Wild

Jul 15
Register Security

CISA sounds alarm over trio of exploited SharePoint flaws

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.