Warlock is a Windows ransomware operation active since at least March 2025 and associated with the threat cluster tracked as GOLD SALEM by Sophos and Storm-2603 by Microsoft. It is also referred to as X2anylock because earlier payloads appended that extension to encrypted files. Warlock appears to be based on the leaked LockBit 3.0 builder and conducts double-extortion operations, encrypting victim systems while exfiltrating selected data for publication through a dedicated leak site. Victims have included government, technology, manufacturing, financial-services, education, critical-infrastructure, and commercial organizations across North America, Europe, Asia, Africa, and South America.
Operators have repeatedly obtained access by exploiting unpatched, internet-facing on-premises Microsoft SharePoint Server vulnerabilities, notably the ToolShell chain, and have also been linked to exploitation of exposed Veeam Backup & Replication and other enterprise applications. Post-compromise activity includes deployment of web shells and remote-access tooling, Active Directory and host reconnaissance, credential theft from LSASS and Windows credential stores, credential replication, creation or modification of privileged accounts, and lateral movement through SMB administrative shares, PsExec, Impacket, PowerShell Remoting, RDP, and remote-management software. Ransomware payloads have been distributed domain-wide using Active Directory Group Policy Objects and startup scripts.
Warlock operators use multiple command-and-control and persistence channels, including abused Velociraptor, Cloudflare Tunnel, Visual Studio Code tunnels, web shells, reverse proxies, and remote-management products. They evade defenses by terminating security processes, including through Bring Your Own Vulnerable Driver techniques using signed vulnerable drivers, and have also used DLL sideloading. Data theft has been performed with renamed Rclone instances to attacker-controlled cloud storage. Microsoft assesses Storm-2603 as China-based with moderate confidence; other researchers have not independently confirmed that attribution.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
11 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Warlock and other groups exploited newly discovered vulnerabilities in internet-exposed, unpatched on-premises Microsoft SharePoint servers. The report identifies the SharePoint ToolShell vulnerability as central to the campaign. | The ransomware encrypted files, appending the extension .x2anylock to each encrypted file (hence Warlock’s alternative naming scheme “X2anylock”).
A high-severity bug in Microsoft SharePoint that’s been exploited since early July has been abused by ransomware, according to an Aug. 10 update to the Cybersecurity and Infrastructure Security Agency's Known Exploited Vulnerabilities (KEV) catalog. CISA offered no more information on the nature of the ransomware attack, but the CVSS 8.8 flaw — CVE-2026-45659 — was added to the agency’s KEV on July 1 and patched by Microsoft in late May. | “They exploited the ToolShell zero-day chain in July 2025 to deploy Warlock ransomware, and now they're back doing the same thing with CVE-2026-45659,” said Calderone.
CISA said attackers were chaining together CVE-2025-49706 (6.5) and CVE-2025-49704 (8.8) to break into SharePoint Servers and, in some cases, deploy Warlock ransomware.
CISA said attackers were chaining together CVE-2025-49706 (6.5) and CVE-2025-49704 (8.8) to break into SharePoint Servers and, in some cases, deploy Warlock ransomware.
Microsoft later confirmed that Storm-2603, a threat actor known for deploying Warlock ransomware specifically through on-premises SharePoint bugs, was among the groups that piled on.
SmarterMail CVE-2026-23760 Storm-2603 (Warlock) ... observed during intrusions that lead to WarLock ransomware deployment or data exfiltration | This is the list of vulnerabilities that have been observed during intrusions that lead to WarLock ransomware deployment or data exfiltration and leaks published to WarLock's Tor Site.
Gladinet CentreStack CVE-2025-14611 Storm-2603 (Warlock) ... observed during intrusions that lead to WarLock ransomware deployment or data exfiltration | This is the list of vulnerabilities that have been observed during intrusions that lead to WarLock ransomware deployment or data exfiltration and leaks published to WarLock's Tor Site.
SolarWinds Web Help Desk CVE-2025-40551 Storm-2603 (Warlock) ... observed during intrusions that lead to WarLock ransomware deployment or data exfiltration | This is the list of vulnerabilities that have been observed during intrusions that lead to WarLock ransomware deployment or data exfiltration and leaks published to WarLock's Tor Site.
The version of Velociraptor observed in this incident was outdated (version 0.73.4.0) and exposed to a privilege escalation vulnerability (CVE-2025-6264), which may have been leveraged for persistence as this vulnerability can lead to arbitrary command execution and endpoint takeover.
CTU researchers also observed GOLD SALEM bypass EDR by using the Bring Your Own Vulnerable Driver (BYOVD) technique and a vulnerable Baidu Antivirus driver renamed googleApiUtil64.sys to terminate the EDR agent. A flaw in this driver (CVE-2024-51324) allows for arbitrary processes to be terminated.
CVE-2025-26399 (CVSS score: 9.8) - A deserialization of untrusted data vulnerability in the AjaxProxy component of SolarWinds Web Help Desk that could allow an attacker to run commands on the host machine. The addition of CVE-2025-26399 comes in the wake of reports from Microsoft and Huntress that threat actors are exploiting security flaws in SolarWinds Web Help Desk to obtain initial access. The activity is believed to be the work of the Warlock ransomware crew.
12 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The ransomware encrypted files, appending the extension .x2anylock to each encrypted file (hence Warlock’s alternative naming scheme “X2anylock”).
Warlock operators exploited vulnerable Microsoft SharePoint servers, maintained multiple C2 channels, disabled security tooling through BYOVD, exfiltrated data with renamed Rclone, and deployed encryption payloads via Active Directory GPO.
Groups including UAC-0238 exploited exposed RDP services to push ransomware variants such as X2anylock, Warlock, and LockBit 3.0 into compromised environments.
Warlock Ransomware Hits US Firms Exploiting SharePoint Zero-Day, Linked to China’s CamoFei APT
GOLD SALEM (also known as Storm-2603) is a financially motivated cybercriminal threat group calling itself Warlock Group responsible for the distribution of the Warlock ransomware.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
"That vulnerability, an authentication bypass that can be used to reset admin passwords..."
22 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
86 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware operation that compromises internet-facing SharePoint servers, establishes domain-wide control, disables endpoint defenses through a vulnerable-driver technique, steals data, and distributes file-encrypting payloads through Group Policy.
Ransomware deployed following exploitation of internet-facing on-premises SharePoint servers. It encrypts files with the .x2anylock extension, drops a "How to decrypt my data.txt" ransom note, terminates security, backup, database, and productivity processes/services, and is described as a customized derivative of the leaked LockBit 3.0 builder.
Ransomware reportedly deployed by Storm-2603 in SharePoint exploitation campaigns; described as being built on the leaked LockBit 3.0 builder.
Ransomware deployed by Storm-2603 following SharePoint exploitation.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.