Warlock, also referred to as GOLD SALEM, is a ransomware threat group that emerged in 2025 and is notable for combining financially motivated extortion with aggressive exploitation of internet-facing enterprise software. Reporting has linked the group to exploitation activity involving Microsoft SharePoint in the ToolShell campaign and to additional edge-application compromises affecting products such as SmarterMail, SolarWinds Web Help Desk, and Gladinet CentreStack. Multiple assessments characterize Warlock as a likely China-based operator, although public reporting does not establish a confirmed relationship to the older Warlock Dark Army name despite the similarity. Warlock operates as a double-extortion ransomware actor, encrypting victim systems while also stealing data for extortion leverage. Victim claims and incident reporting indicate targeting across a broad range of sectors, including government, aerospace, nuclear energy, telecommunications, manufacturing, and other enterprise environments. The group became visible quickly after first appearing in mid-2025 and was assessed as having posted dozens of victims within its first months of activity. A defining feature of Warlock tradecraft is heavy use of defense-evasion tooling, especially bring-your-own-vulnerable-driver techniques to disable endpoint protection. Warlock has been associated with repeated deployment of multiple EDR-killer tools within a single intrusion, sometimes using several alternatives redundantly until one succeeds. Public reporting ties the group to HexKiller, an EDR-killing utility previously considered exclusive to Warlock before later appearing in other actors’ intrusions, as well as to abuse of vulnerable drivers from several security and system software vendors. Researchers have also noted signs that at least one Warlock EDR-killer implementation may have been AI-assisted. Observed Warlock intrusions show a mature post-compromise toolkit spanning credential theft, remote administration, lateral movement, exfiltration, and living-off-the-land execution. Reported tooling includes common offensive frameworks and administrative utilities, cloud and tunneling services, remote management software, and credential-access tools. Warlock has also been noted for adapting legitimate software for malicious purposes, including early malicious use of Velociraptor and abuse patterns involving Visual Studio Code tunneling techniques. Warlock is associated with rapid exploitation of exposed edge infrastructure rather than reliance on traditional phishing-centric access. Reporting also notes overlap or proximity in some campaigns with activity tracked as Storm-2603, including incidents where multiple ransomware families or variants were deployed. While attribution details remain incomplete, the group is consistently described as a technically capable ransomware operator with a strong emphasis on zero-day or n-day exploitation of externally exposed systems, robust anti-EDR measures, and high-tempo enterprise intrusion operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
35 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
8 malware families attributed to this actor across reporting.
3 additional families tracked in Mallory.
6 CVEs this actor has used in observed campaigns. 6 of them exploited in the wild.
"CVE-2026-23760 is an authentication bypass flaw that could allow any user to reset the SmarterMail system administrator password by sending a specially crafted HTTP request." / "ReliaQuest said it identified activity likely linked to Warlock that involved the abuse of CVE-2026-23760 to bypass authentication and stage the ransomware payload..."
CVE-2026-24423, on the other hand, exploits a weakness in the ConnectToHub API method to achieve unauthenticated remote code execution (RCE).
"Colt had an on-premise SharePoint server that had already been backdoored (via CVE-2025-53770) in the recent mass-hack wave by the time it was patched."
CVE-2014-8361 9.3 Realtek SDK, IoT Devices, Network Equipment Warlock, Sinobi, Beast Link
CVE-2025-26399 (CVSS score: 9.8) - A deserialization of untrusted data vulnerability in the AjaxProxy component of SolarWinds Web Help Desk that could allow an attacker to run commands on the host machine.
1 more CVE tied to this actor tracked in Mallory.
8 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as prior attribution context for the third-party EDR killer HexKiller.
Referenced as the ransomware gang previously associated with HexKiller before the tool appeared in Gentlemen intrusions.
Referenced as the group previously exclusively attributed with HexKiller.
Referenced as a ransomware gang previously associated with the HexKiller EDR-killer tool.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.