Warlock is a China-linked ransomware operation also tracked as GOLD SALEM, Longlegs, Storm-2603, and Water Manaul. It emerged publicly in June 2025 and gained prominence through exploitation of the ToolShell vulnerabilities in on-premises Microsoft SharePoint Server, including CVE-2025-49704 and CVE-2025-49706. Its victims include technology companies, manufacturers, government bodies, universities, financial-services organizations, telecommunications providers, and water utilities. Its targeting spans multiple continents, with substantial victim counts in the United States, Germany, Russia, and the United Kingdom, and attacks against Portuguese- and Spanish-speaking organizations across Europe, Africa, and Latin America. Its China linkage does not establish state sponsorship. Warlock primarily gains access by exploiting vulnerable internet-facing enterprise applications. Besides SharePoint, it has exploited SmarterTools SmarterMail and SolarWinds Web Help Desk. SharePoint intrusions involve web-shell deployment and theft of ASP.NET machine keys, which enable the attackers to forge validly signed payloads for remote code execution. Post-compromise activity includes Active Directory reconnaissance, credential dumping with Mimikatz, extraction of local password hashes, DCSync, administrative-account manipulation, and lateral movement through SMB, PsExec, PowerShell Remoting, and RDP. The operation uses DLL sideloading, living-off-the-land techniques, and legitimate administration tools to execute payloads and maintain access. Observed tools include Cobalt Strike, Velociraptor, TightVNC, and Zoho Assist Unattended Agent. It establishes redundant remote-access channels through Cloudflare Tunnel, Visual Studio Code tunnels, and reverse SOCKS proxies. Warlock uses bring-your-own-vulnerable-driver attacks and security-disabling tools, including HexKiller, to terminate endpoint protection processes, rotating drivers across campaigns. Warlock exfiltrates selected victim data with Rclone and operates a public victim leak site. It stages ransomware and security-disabling tooling in domain replication shares and uses Active Directory Group Policy to distribute and execute payloads across domain-joined systems. Its ransomware encrypts files and terminates backup, database, security, and productivity processes to impede recovery and maximize disruption.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
49 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
8 malware families attributed to this actor across reporting.
3 additional families tracked in Mallory.
7 CVEs this actor has used in observed campaigns. 7 of them exploited in the wild.
Warlock attracted attention in mid-2025 for zero-day exploitation of the ToolShell SharePoint vulnerabilities to install ransomware. The report says ToolShell exploitation remains an effective initial-access method against unpatched or otherwise unprotected SharePoint deployments.
"CVE-2026-23760 is an authentication bypass flaw that could allow any user to reset the SmarterMail system administrator password by sending a specially crafted HTTP request." / "ReliaQuest said it identified activity likely linked to Warlock that involved the abuse of CVE-2026-23760 to bypass authentication and stage the ransomware payload..."
CVE-2026-24423, on the other hand, exploits a weakness in the ConnectToHub API method to achieve unauthenticated remote code execution (RCE).
The attackers abused the legitimate but vulnerable K7RKScan.sys driver (CVE-2025-1055) in a Bring Your Own Vulnerable Driver attack to disable security software. The same driver had previously been abused by DragonForce ransomware actors.
CVE-2014-8361 9.3 Realtek SDK, IoT Devices, Network Equipment Warlock, Sinobi, Beast Link
2 more CVEs tied to this actor tracked in Mallory.
20 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as a ransomware group that maintains multiple vulnerable drivers and changes drivers in response to blocklist updates.
China-linked cluster exploiting SharePoint vulnerabilities and deploying its namesake ransomware against organizations in Portuguese- and Spanish-speaking regions. Discussed as contextual background; the content does not connect Warlock to exploitation of CVE-2026-96940.
A China-linked actor exploiting Microsoft SharePoint vulnerabilities to deploy Warlock ransomware. Mentioned as background to the Exchange Server vulnerability disclosure; the content does not connect Warlock to exploitation of CVE-2026-96940.
A suspected China-linked threat actor exploiting on-premises SharePoint vulnerabilities to compromise networks, disable security software, and deploy Warlock ransomware. Recent attacks affected at least four organizations across Portuguese- and Spanish-speaking countries in Europe, Africa, and Latin America. The content also links the group to the compromise of SmarterTools through an unpatched SmarterMail instance. Chinese state sponsorship is not established by the content.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.