Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
5 malware familiesExploits CVEs in the wild

Warlock

Also known aswarlock

Warlock is a ransomware group first observed posting victims in June 2025. Reporting in the provided content describes it as a likely China-based operator and links it to exploitation of internet-facing software, including the ToolShell SharePoint zero-day campaign, as well as exploitation involving SmarterMail, SolarWinds Web Help Desk, and Gladinet CentreStack. Sophos reported that Warlock compromised more than 60 organizations in six months and targeted high-value sectors including nuclear energy, aerospace, and government. The group has also been described as remaining operational after its leak site went silent in November 2025. Warlock is associated with aggressive defense evasion, especially repeated use of multiple EDR killers and BYOVD techniques. ESET reported that Warlock routinely deployed multiple EDR killers per intrusion and abused at least nine different vulnerable drivers. Drivers and BYOVD components directly mentioned in the content include Antiy, NSecSoft/NSecKrnl.sys, Rising Antivirus, VMTools, the Baidu Antivirus BdApi driver googleApiUtil64.sys used by HexKiller, and signed Chinese drivers used to disable antivirus protections. Trend Micro reported that newer Warlock campaigns replaced googleApiUtil64.sys with NSecKrnl.sys. The content also states that affiliates of Qilin and Warlock used an msimg32.dll side-loading chain in April 2026 to load rwdrv.sys and hlpdrv.sys and terminate more than 300 endpoint agent drivers. HexKiller is repeatedly described as an EDR killer previously associated exclusively with the Warlock ransomware gang. ESET also assessed that some Warlock EDR-killer tooling showed signs suggestive of AI-assisted development. The content further states that Warlock adapted the VS Code abuse technique previously used by Mustang Panda and pioneered malicious use of Velociraptor. Tools observed across intrusions leading to Warlock ransomware deployment include Everything.exe, Radmin, Mimikatz, Cobalt Strike, SecurityCheck, TightVNC, Veeam-Get-Creds, Velociraptor, Impacket, Cloudflared, PsExec, OpenSSH, PowerShell Remoting, RDP Patcher, VS Code Tunnel, RClone, MinIO, Azure Blob Storage, Supabase, Catbox[.]moe, and msiexec. Trend Micro additionally reported use of TightVNC for persistence, PsExec for lateral movement, RDP Patcher for concurrent RDP sessions, Velociraptor for command-and-control, Visual Studio Code with Cloudflare Tunnel for tunneling C2, Yuze for intranet penetration and reverse proxy connectivity, and Rclone for exfiltration. The content also notes that Storm-2603 deployed a ransomware variant linked to the Warlock group, and that the Sophos article URL associates the operation with the name Gold Salem. No higher-confidence alias relationship beyond those mentions is established in the provided material.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

MITRE ATT&CK

Tradecraft

36 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

12 of 15 tactics44 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0001
Initial Access
3 techniques
T1078
Valid Accounts
T1133×2
External Remote Services
T1190×12
Exploit Public-Facing Application
TA0002
Execution
2 techniques
T1059×2
Command and Scripting Interpreter
T1203
Exploitation for Client Execution
TA0003
Persistence
5 techniques
T1078
Valid Accounts
T1098
Account Manipulation
T1133×2
External Remote Services
T1136×2
Create Account
T1505
Server Software Component
T1505.003
Web Shell
TA0004
Privilege Escalation
3 techniques
T1068×13
Exploitation for Privilege Escalation
T1078
Valid Accounts
T1098
Account Manipulation
TA0005
Stealth
6 techniques
T1027×2
Obfuscated Files or Information
T1036
Masquerading
T1070
Indicator Removal
T1070.004
File Deletion
T1078
Valid Accounts
T1218
System Binary Proxy Execution
T1218.007×2
Msiexec
T1497
Virtualization/Sandbox Evasion
T1497.003×2
Time Based Checks
TA0006
Credential Access
2 techniques
T1003
OS Credential Dumping
T1003.001
LSASS Memory
T1212
Exploitation for Credential Access
TA0007
Discovery
1 technique
T1497
Virtualization/Sandbox Evasion
T1497.003×2
Time Based Checks
TA0008
Lateral Movement
1 technique
T1021×6
Remote Services
T1021.001×3
Remote Desktop Protocol
T1021.002×3
SMB/Windows Admin Shares
T1021.004
SSH
T1021.006
Windows Remote Management
TA0009
Collection
2 techniques
T1213
Data from Information Repositories
T1560
Archive Collected Data
TA0011
Command and Control
4 techniques
T1071×2
Application Layer Protocol
T1071.001
Web Protocols
T1090×2
Proxy
T1105×5
Ingress Tool Transfer
T1219×3
Remote Access Tools
TA0010
Exfiltration
3 techniques
T1041×2
Exfiltration Over C2 Channel
T1048
Exfiltration Over Alternative Protocol
T1567×2
Exfiltration Over Web Service
TA0040
Impact
1 technique
T1486×8
Data Encrypted for Impact
WEAPONIZED

Associated vulnerabilities

5 CVEs this actor has used in observed campaigns. 5 of them exploited in the wild.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping36

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal5

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs5

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.