Warlock is a ransomware family active since at least March 2025 and publicly advertised from June 2025. It has been associated with the threat cluster tracked as Storm-2603 by Microsoft and GOLD SALEM by Sophos. Multiple investigations link Warlock activity to exploitation of internet-facing enterprise software, especially on-premises Microsoft SharePoint through the ToolShell vulnerability chain, and also to compromises involving other exposed applications. Observed victims span government, healthcare, manufacturing, telecommunications, agriculture, energy and natural resources, and other commercial sectors across North America, Europe, South America, Latin America, and Asia-Pacific.
Warlock intrusions commonly involve exploitation of public-facing applications for initial access, followed by deployment of web shells or other remote-access tooling, credential theft, lateral movement, defense evasion, data exfiltration, and ransomware deployment. Reported post-compromise tradecraft includes theft of credentials from LSASS, use of PsExec, Impacket, WMI, RDP, WinRM, and Group Policy Objects for propagation and payload distribution. Operators have also used legitimate or dual-use remote management and incident-response tools such as Zoho Assist and Velociraptor to maintain access and blend into administrative activity.
Defense evasion is a notable feature of Warlock operations. Observed campaigns used Bring Your Own Vulnerable Driver techniques to tamper with or terminate endpoint security products, and some reporting also describes DLL sideloading chains used to load vulnerable signed drivers for broad endpoint-agent disruption. Persistence mechanisms seen in Warlock-linked intrusions include web shells, scheduled tasks, remote management agents, and tunneling or remote-access channels established through administrative tooling.
Warlock is also tied to double-extortion style operations. Victim organizations have been listed on a leak site, and reporting links some intrusions both to ransomware deployment and to data theft followed by publication or sale claims. The group’s operational model appears compatible with extortion-focused ransomware activity rather than encryption alone.
Microsoft has assessed Storm-2603 with moderate confidence as China-based, but that attribution has not been universally corroborated. What is well supported is the repeated association between Storm-2603/GOLD SALEM and Warlock deployments, particularly in attacks exploiting on-premises SharePoint vulnerabilities and using GPO-based ransomware rollout inside compromised Windows environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
11 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CISA said attackers were chaining together CVE-2025-49706 (6.5) and CVE-2025-49704 (8.8) to break into SharePoint Servers and, in some cases, deploy Warlock ransomware.
CISA said attackers were chaining together CVE-2025-49706 (6.5) and CVE-2025-49704 (8.8) to break into SharePoint Servers and, in some cases, deploy Warlock ransomware.
Microsoft оценила вероятность эксплуатации CVE-2026-45659 как "Exploitation Less Likely". Через 40 дней CISA маркировала active exploitation и дала федеральным агентствам три дня на патч... CVE-2026-45659 - десериализация небезопасных данных (CWE-502)... CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H.
Microsoft later confirmed that Storm-2603, a threat actor known for deploying Warlock ransomware specifically through on-premises SharePoint bugs, was among the groups that piled on.
Microsoft later confirmed that Storm-2603, a threat actor known for deploying Warlock ransomware specifically through on-premises SharePoint bugs, was among the groups that piled on.
SmarterMail CVE-2026-23760 Storm-2603 (Warlock) ... observed during intrusions that lead to WarLock ransomware deployment or data exfiltration | This is the list of vulnerabilities that have been observed during intrusions that lead to WarLock ransomware deployment or data exfiltration and leaks published to WarLock's Tor Site.
Gladinet CentreStack CVE-2025-14611 Storm-2603 (Warlock) ... observed during intrusions that lead to WarLock ransomware deployment or data exfiltration | This is the list of vulnerabilities that have been observed during intrusions that lead to WarLock ransomware deployment or data exfiltration and leaks published to WarLock's Tor Site.
SolarWinds Web Help Desk CVE-2025-40551 Storm-2603 (Warlock) ... observed during intrusions that lead to WarLock ransomware deployment or data exfiltration | This is the list of vulnerabilities that have been observed during intrusions that lead to WarLock ransomware deployment or data exfiltration and leaks published to WarLock's Tor Site.
The version of Velociraptor observed in this incident was outdated (version 0.73.4.0) and exposed to a privilege escalation vulnerability (CVE-2025-6264), which may have been leveraged for persistence as this vulnerability can lead to arbitrary command execution and endpoint takeover.
CTU researchers also observed GOLD SALEM bypass EDR by using the Bring Your Own Vulnerable Driver (BYOVD) technique and a vulnerable Baidu Antivirus driver renamed googleApiUtil64.sys to terminate the EDR agent. A flaw in this driver (CVE-2024-51324) allows for arbitrary processes to be terminated.
CVE-2025-26399 (CVSS score: 9.8) - A deserialization of untrusted data vulnerability in the AjaxProxy component of SolarWinds Web Help Desk that could allow an attacker to run commands on the host machine. The addition of CVE-2025-26399 comes in the wake of reports from Microsoft and Huntress that threat actors are exploiting security flaws in SolarWinds Web Help Desk to obtain initial access. The activity is believed to be the work of the Warlock ransomware crew.
10 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Talos IR responded to Sinobi ransomware for the first time, as well as previously seen variants Nitrogen and Warlock... In one engagement, we observed Warlock ransomware operators (also known as Storm-2603) deploying an installer for the RMM tool Zoho Assist Unattended Agent.
Groups including UAC-0238 exploited exposed RDP services to push ransomware variants such as X2anylock, Warlock, and LockBit 3.0 into compromised environments.
Warlock Ransomware Hits US Firms Exploiting SharePoint Zero-Day, Linked to China’s CamoFei APT
GOLD SALEM (also known as Storm-2603) is a financially motivated cybercriminal threat group calling itself Warlock Group responsible for the distribution of the Warlock ransomware.
"WarLock ransomware hit Colt Telecom, causing outages in hosting, porting, Colt Online, and Voice API since August 12."
"Storm-2603 was using the exploit to deploy Warlock and another ransomware payload, LockBit."
5 distinct techniques documented for this family, organized by ATT&CK tactic.
"That vulnerability, an authentication bypass that can be used to reset admin passwords..."
22 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
81 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware operators observed deploying Zoho Assist Unattended Agent to gain persistent, stealthy remote access without an active user session; activity was consistent with a successful Warlock ransomware attack observed in May.
Ransomware deployed in some SharePoint Server intrusions involving chained exploitation of ToolShell vulnerabilities.
Ransomware deployed after SharePoint compromise; the article describes it as the end-stage payload in attacks exploiting on-premises SharePoint vulnerabilities.
Ransomware deployed via exploitation of on-premises SharePoint vulnerabilities by Storm-2603.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.