GOLD SALEM is a ransomware threat actor tracked by Sophos Counter Threat Unit as the Warlock Group and by Microsoft as Storm-2603. The group has compromised networks and deployed Warlock ransomware since March 2025. Through mid-September 2025 it had publicly listed 60 victims across North America, Europe, and South America, including small commercial entities, government entities, and large multinational corporations. The group operates a Tor-based leak site to publish victim names and stolen data, has claimed data sales to private buyers, and used underground forum activity on RAMP to solicit exploits for Veeam, ESXi, and SharePoint, tools to disable EDR and other security products, and cooperation from initial access brokers. Sophos stated it was unclear whether the actor was seeking access for its own intrusions, recruiting affiliates for a ransomware-as-a-service model, or both. Observed tradecraft includes exploitation of the SharePoint ToolShell exploit chain for initial access, specifically CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771; deployment of an ASPX web shell enabling remote command execution via cmd.exe under w3wp.exe; use of curl to download a Golang-based WebSockets backdoor for persistence; and EDR bypass via BYOVD using a vulnerable Baidu Antivirus driver renamed googleApiUtil64.sys, exploiting CVE-2024-51324 to terminate security processes. Additional observed activity includes credential theft from LSASS using Mimikatz, lateral movement with PsExec and Impacket, ransomware deployment via Group Policy Objects, and abuse of the legitimate Velociraptor DFIR tool to establish a Visual Studio Code network tunnel. Microsoft assessed Storm-2603 with moderate confidence as China-based, but Sophos said it had insufficient evidence to corroborate that attribution. GOLD SALEM largely avoided targeting organizations in China and Russia, though it posted a Russia-based victim in September 2025, which Sophos assessed may suggest the group operates outside Russian jurisdiction. Known aliases and related tracking names directly mentioned in the content are Warlock Group and Storm-2603.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
1 malware family attributed to this actor across reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced only as a separate ransomware operation previously affecting the same victim later listed by GOLD SALEM.
Referenced as a separate ransomware operation that previously victimized the same U.S.-based construction contractor later listed by GOLD SALEM.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.