Warlock is a ransomware operation active since at least March 2025, with public victim postings beginning in June 2025. It has been tracked as GOLD SALEM by Sophos and is closely associated with the threat actor Storm-2603, which Microsoft has assessed with moderate confidence as China-based, although that geographic attribution is not universally corroborated. Warlock has targeted organizations across multiple regions including North America, Europe, South America, Latin America, and Asia-Pacific, with observed victims spanning government, telecommunications, agriculture, energy and natural resources, and commercial enterprises.
Warlock intrusions have repeatedly been linked to exploitation of internet-facing on-premises Microsoft SharePoint vulnerabilities, especially the ToolShell exploit chain, and later reporting also associates the operation with exploitation of other enterprise software vulnerabilities. In observed SharePoint compromises, attackers obtained code execution on vulnerable servers, deployed web shells for command execution, stole credentials from LSASS using Mimikatz, created local and domain administrative accounts, and moved laterally with tools such as PsExec, Impacket, WMI, and PowerShell remoting. Microsoft also observed modification of Group Policy Objects to distribute the ransomware payload across compromised environments.
The operation demonstrates mature post-compromise tradecraft beyond encryption. Reported activity includes persistence through web shells, scheduled tasks, IIS component manipulation, and secondary backdoors; use of remote access channels such as Cloudflare tunneling, Zoho Assist, OpenSSH, and Visual Studio Code tunnels; and data theft and leak-site extortion. Warlock maintains a Tor-based leak site and has published victim names and stolen data, indicating a double-extortion model in which exfiltration is an important component of operations.
Defense evasion is a notable feature of Warlock-linked intrusions. Researchers have observed Bring Your Own Vulnerable Driver techniques used to disable or tamper with endpoint security products, including vulnerable antivirus or utility drivers and, in later reporting, DLL sideloading chains used to load signed vulnerable drivers for mass termination of endpoint agents. Additional observed tooling across Warlock-related incidents includes Velociraptor, Cobalt Strike, Rclone, and other utilities associated with reconnaissance, credential access, remote administration, and exfiltration.
Warlock appears both as a distinct ransomware brand and as malware deployed by overlapping or multi-actor intrusion sets. Incident reporting has described environments where Storm-2603 activity overlapped with unrelated actors, complicating attribution. Even so, the strongest consistent pattern is exploitation of exposed enterprise services for initial access, rapid privilege escalation and lateral movement, suppression of defenses, theft of data, and enterprise-wide ransomware deployment.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
11 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CISA said attackers were chaining together CVE-2025-49706 (6.5) and CVE-2025-49704 (8.8) to break into SharePoint Servers and, in some cases, deploy Warlock ransomware.
CISA said attackers were chaining together CVE-2025-49706 (6.5) and CVE-2025-49704 (8.8) to break into SharePoint Servers and, in some cases, deploy Warlock ransomware.
Microsoft оценила вероятность эксплуатации CVE-2026-45659 как "Exploitation Less Likely". Через 40 дней CISA маркировала active exploitation и дала федеральным агентствам три дня на патч... CVE-2026-45659 - десериализация небезопасных данных (CWE-502)... CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H.
Microsoft later confirmed that Storm-2603, a threat actor known for deploying Warlock ransomware specifically through on-premises SharePoint bugs, was among the groups that piled on.
Microsoft later confirmed that Storm-2603, a threat actor known for deploying Warlock ransomware specifically through on-premises SharePoint bugs, was among the groups that piled on.
SmarterMail CVE-2026-23760 Storm-2603 (Warlock) ... observed during intrusions that lead to WarLock ransomware deployment or data exfiltration | This is the list of vulnerabilities that have been observed during intrusions that lead to WarLock ransomware deployment or data exfiltration and leaks published to WarLock's Tor Site.
Gladinet CentreStack CVE-2025-14611 Storm-2603 (Warlock) ... observed during intrusions that lead to WarLock ransomware deployment or data exfiltration | This is the list of vulnerabilities that have been observed during intrusions that lead to WarLock ransomware deployment or data exfiltration and leaks published to WarLock's Tor Site.
SolarWinds Web Help Desk CVE-2025-40551 Storm-2603 (Warlock) ... observed during intrusions that lead to WarLock ransomware deployment or data exfiltration | This is the list of vulnerabilities that have been observed during intrusions that lead to WarLock ransomware deployment or data exfiltration and leaks published to WarLock's Tor Site.
The version of Velociraptor observed in this incident was outdated (version 0.73.4.0) and exposed to a privilege escalation vulnerability (CVE-2025-6264), which may have been leveraged for persistence as this vulnerability can lead to arbitrary command execution and endpoint takeover.
CTU researchers also observed GOLD SALEM bypass EDR by using the Bring Your Own Vulnerable Driver (BYOVD) technique and a vulnerable Baidu Antivirus driver renamed googleApiUtil64.sys to terminate the EDR agent. A flaw in this driver (CVE-2024-51324) allows for arbitrary processes to be terminated.
CVE-2025-26399 (CVSS score: 9.8) - A deserialization of untrusted data vulnerability in the AjaxProxy component of SolarWinds Web Help Desk that could allow an attacker to run commands on the host machine. The addition of CVE-2025-26399 comes in the wake of reports from Microsoft and Huntress that threat actors are exploiting security flaws in SolarWinds Web Help Desk to obtain initial access. The activity is believed to be the work of the Warlock ransomware crew.
10 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Группировка Storm-2603, по данным Microsoft Incident Response (опубликовано The Hacker News), эксплуатирует уязвимости on-premises SharePoint для развёртывания ransomware Warlock с середины 2025 года.
Groups including UAC-0238 exploited exposed RDP services to push ransomware variants such as X2anylock, Warlock, and LockBit 3.0 into compromised environments.
Warlock Ransomware Hits US Firms Exploiting SharePoint Zero-Day, Linked to China’s CamoFei APT
GOLD SALEM (also known as Storm-2603) is a financially motivated cybercriminal threat group calling itself Warlock Group responsible for the distribution of the Warlock ransomware.
"WarLock ransomware hit Colt Telecom, causing outages in hosting, porting, Colt Online, and Voice API since August 12."
"Storm-2603 was using the exploit to deploy Warlock and another ransomware payload, LockBit."
5 distinct techniques documented for this family, organized by ATT&CK tactic.
"That vulnerability, an authentication bypass that can be used to reset admin passwords..."
22 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
80 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware deployed in some SharePoint Server intrusions involving chained exploitation of ToolShell vulnerabilities.
Ransomware deployed after SharePoint compromise; the article describes it as the end-stage payload in attacks exploiting on-premises SharePoint vulnerabilities.
Ransomware deployed via exploitation of on-premises SharePoint vulnerabilities by Storm-2603.
Ransomware deployed by Storm-2603 in attacks that often exploit known vulnerabilities in on-premises SharePoint servers.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.