Skip to main content
Mallory
4 malware familiesExploits CVEs in the wild

Warlock

Also known aswarlock

Warlock is a ransomware group active since at least June 2025. It is also referred to in the provided reporting as WarLock, Warlock Group, Water Manaul, Storm-2603, and in one Sophos-linked context as Gold Salem. Multiple sources in the content describe the group as attributed to Chinese threat actors, with reporting specifically stating that Warlock Group (aka Storm-2603) is a ransomware gang attributed to Chinese actors and that ReliaQuest linked related activity to Storm-2603 with moderate-to-high confidence. The group has been reported posting victims from June 2025 and reached 43 total listings in Q3 2025; other reporting says it hit more than 60 organizations in six months. Victim sectors directly mentioned in the content include nuclear energy, aerospace, government, telecommunications, and organizations using SmarterMail/SmarterTrack. Named victims or claimed victims in the content include Talal Abu-Ghazaleh Global, Hitachi, Primrose Oil Company, Colt Technology Service Group, Cleary Building Corporation, and SmarterTools-related environments. Warlock is described as a closed ransomware group that does not rely on affiliates and develops proprietary EDR killers from scratch. ESET reporting in the content says Warlock deploys dozens of EDR killers per intrusion until one works, and multiple samples showed patterns consistent with AI-assisted code generation. ESET also strongly suspects Warlock uses artificial intelligence to help write and update its EDR killer code. Tactics and techniques directly described in the content include exploitation of unpatched Microsoft SharePoint servers, including reporting tied to CVE-2025-53770 and references to CVE-2025-49704, CVE-2025-49706, and CVE-2025-53771; exploitation of SolarWinds Web Help Desk vulnerabilities for initial access, including activity associated with CVE-2025-26399; and exploitation of SmarterMail vulnerabilities, including CVE-2026-23760 and CVE-2026-24423. The group is also described as using chains of zero-day vulnerabilities in some intrusions. For defense evasion, Warlock has used BYOVD techniques and signed Chinese drivers to disable antivirus or security products. Reporting in the content says the group used googleApiUtil64.sys previously and later NSecKrnl.sys to terminate security products at kernel level. The group is also described as neutralizing antivirus protections and repeatedly attempting multiple EDR killers during an intrusion. Operational tooling directly mentioned includes TightVNC for persistence, PsExec for lateral movement, RDP Patcher for concurrent RDP sessions, Velociraptor for command-and-control or post-compromise activity, Visual Studio Code with Cloudflare Tunnel for tunneling C2 traffic, Yuze for intranet penetration and reverse proxy connectivity, Rclone for exfiltration to S3 buckets, SimpleHelp, vulnerable WinRAR versions, and web shells and files such as spinstall0.aspx, spinstall.aspx, spinstall1.aspx, spinstall2.aspx, IIS_Server_dll.dll, SharpHostInfo.x64.exe, xd.exe, and debug_dev.js. The group uses double extortion. The provided extortion note states that Warlock Group encrypts victim data, exfiltrates data, threatens public release or sale of stolen information, and offers decryption and deletion of stolen data in exchange for payment.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

MITRE ATT&CK

Tradecraft

32 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

13 of 15 tactics42 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0001
Initial Access
3 techniques
T1078
Valid Accounts
T1133×2
External Remote Services
T1190×12
Exploit Public-Facing Application
TA0002
Execution
2 techniques
T1059×3
Command and Scripting Interpreter
T1203
Exploitation for Client Execution
TA0003
Persistence
6 techniques
T1078
Valid Accounts
T1098
Account Manipulation
T1133×2
External Remote Services
T1136×2
Create Account
T1136.002
Domain Account
T1505
Server Software Component
T1505.003
Web Shell
T1556
Modify Authentication Process
TA0004
Privilege Escalation
3 techniques
T1068×7
Exploitation for Privilege Escalation
T1078
Valid Accounts
T1098
Account Manipulation
TA0005
Stealth
5 techniques
T1027
Obfuscated Files or Information
T1036×2
Masquerading
T1078
Valid Accounts
T1218
System Binary Proxy Execution
T1218.007
Msiexec
T1497
Virtualization/Sandbox Evasion
T1497.003×3
Time Based Checks
TA0112
Defense Impairment
1 technique
T1556
Modify Authentication Process
TA0006
Credential Access
2 techniques
T1212
Exploitation for Credential Access
T1556
Modify Authentication Process
TA0007
Discovery
1 technique
T1497
Virtualization/Sandbox Evasion
T1497.003×3
Time Based Checks
TA0008
Lateral Movement
2 techniques
T1021×5
Remote Services
T1021.001×2
Remote Desktop Protocol
T1021.002×2
SMB/Windows Admin Shares
T1210
Exploitation of Remote Services
TA0009
Collection
1 technique
T1560
Archive Collected Data
TA0011
Command and Control
4 techniques
T1071×2
Application Layer Protocol
T1071.001
Web Protocols
T1090×2
Proxy
T1105×4
Ingress Tool Transfer
T1219×2
Remote Access Tools
TA0010
Exfiltration
3 techniques
T1041
Exfiltration Over C2 Channel
T1048
Exfiltration Over Alternative Protocol
T1567
Exfiltration Over Web Service
TA0040
Impact
1 technique
T1486×9
Data Encrypted for Impact
WEAPONIZED

Associated vulnerabilities

5 CVEs this actor has used in observed campaigns. 5 of them exploited in the wild.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping32

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal4

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs5

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.