Warlock ransomware operators exploited Microsoft SharePoint’s ToolShell vulnerabilities, including CVE-2025-53770, to compromise enterprise networks, steal data and deploy ransomware. Microsoft tracks the actor as Storm-2603; Palo Alto Networks Unit 42 assessed with high confidence that it matches its CL-CRI-1040 cluster. The operation uses the Project AK47 toolset, including a DNS/HTTP command-and-control backdoor, DLL sideloading loaders and AK47/X2ANYLOCK ransomware. Warlock is a LockBit 3.0 derivative that appends the .x2anylock extension to encrypted files. Researchers linked the operators to earlier LockBit affiliate activity and a Warlock-branded double-extortion site, with victims spanning multiple continents and sectors, including critical infrastructure.
Observed intrusions involved web shells, credential theft, lateral movement, Group Policy abuse, security-tool disabling and RClone-based data exfiltration; attackers also exploited outdated Veeam installations vulnerable to CVE-2023-27532. Symantec and Carbon Black found malicious 7z.dll loaders and defense-evasion tools using a stolen coolschool signing certificate and a vulnerable Baidu driver in attacks against a Middle Eastern engineering company and a U.S. firm. Certificate reuse suggests a possible connection to CamoFei/ChamelGang, but that historical link and a proposed mix of espionage and financially motivated activity remain tentative. Microsoft assessed Storm-2603 as China-based, while Unit 42 reported insufficient evidence for confident nation-state attribution. Defenders should prioritize SharePoint and Veeam patching and hunt for suspicious DLL loading, vulnerable-driver abuse, unauthorized Group Policy changes and AK47 command-and-control activity.

See which actors are running it and whether you're in range.
18 events from the most recent confirmed update back to the earliest known activity.
In an early August 2025 attack against a U.S. firm, ransomware attempted to encrypt files with the .x2anylock extension while its ransom note identified the attacker as Warlock. The attack also deployed a defense-evasion tool signed with the stolen coolschool certificate and using a vulnerable Baidu driver.
An early August 2025 attack against an engineering company in the Middle East used legitimate 7z.exe to sideload a malicious 7z.dll loader. The attackers also deployed a defense-evasion tool signed with the stolen coolschool certificate that used a vulnerable Baidu driver to attempt to disable security software.
Check Point published research finding that Storm-2603 used multiple ransomware payloads, sometimes bundled together, and frequently deployed them through DLL sideloading. The actor also used a custom command-and-control framework apparently named ak47c2.
Attackers deploying Warlock were discovered exploiting the Microsoft SharePoint ToolShell zero-day vulnerability CVE-2025-53770 on July 19, 2025. Storm-2603 used ToolShell to deploy both Warlock and LockBit ransomware.
Warlock first appeared in June 2025 and made its public debut on the Russian-language RAMP forum. The Warlock Client Leaked Data Show site also emerged that month, displaying the same negotiation Tox ID used by AK47 ransomware.
A compromise and leak of LockBit 3.0 infrastructure exposed a database containing negotiation messages, Bitcoin wallet addresses, affiliate information, and operational details. Unit 42 subsequently used the leaked records to investigate links to AK47 and Warlock.
The LockBit affiliate account "wlteaml" was registered on April 22, 2025. Unit 42 later found that the account used the same Tox ID as AK47 ransomware ransom notes, connecting the operations.
Unit 42 observed the earliest AK47/X2ANYLOCK ransomware version in early April 2025. An initial prototype created ransom notes without encrypting files.
In early April 2025, dnsclient was updated to version 202504. The update removed JSON from its communications format and introduced session-key-based task handling.
The AK47C2 httpclient variant was under development by at least late March 2025. It used HTTP POST requests through curl for command-and-control communications.
Unit 42 traced development of the AK47C2 dnsclient variant to at least early March 2025. Its early version used encoded DNS communications for command execution and was associated with the CL-CRI-1040 activity cluster.
TeamT5 linked a stolen coolschool signing certificate to CamoFei in 2022. The certificate had been used to sign Cobalt Strike and BYOVD-related malware and also signed CamoFei's CatB ransomware.
CamoFei, also known as ChamelGang, was active by at least 2019, conducting espionage, denial-of-service attacks, and ransomware operations. Researchers later identified certificate reuse suggesting a possible, unconfirmed connection to Warlock.
Research into the two August attacks connected Warlock's defense-evasion tools to the stolen coolschool certificate previously associated with CamoFei and CatB ransomware, and published loader, backdoor, and ransomware indicators. The researchers treated the historical actor connection and a possible mix of contracted espionage and ransomware activity as tentative.
Trend Micro reported that Warlock was a customized LockBit 3.0 derivative and documented SharePoint exploitation, credential theft, lateral movement, RClone exfiltration, and exploitation of CVE-2023-27532 in outdated Veeam environments. It suggested possible Anylock and Black Basta connections without establishing the Black Basta link conclusively.
Unit 42 assessed with high confidence that CL-CRI-1040 was likely the same actor as Storm-2603, documenting its Project AK47 backdoors, ransomware, and sideloading loaders. It linked the actor to LockBit affiliate activity and the Warlock leak site but said it lacked sufficient direct evidence for confident nation-state attribution.
Microsoft identified Budworm, Sheathminer, and Storm-2603 as China-linked actors exploiting ToolShell before patching. Storm-2603 was the actor associated with Warlock and LockBit deployment.
Within days of its public debut, Warlock claimed at least 16 attacks. Half of the claimed attacks targeted government agencies in Portugal, Croatia, and Turkey.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 43 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
4 references tracked. Mallory keeps watching after this page renders.
security.com
Open sourcetrendmicro.com
Open sourceunit42.paloaltonetworks.com
Open sourceresearch.checkpoint.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.