Warlock is a ransomware threat group first observed in 2025 and also tracked as Storm-2603 and GOLD SALEM. It is distinct from the older Warlock Dark Army name despite the similarity. The group is notable for combining ransomware operations with aggressive exploitation of internet-facing enterprise software, including zero-day and n-day vulnerabilities affecting edge and collaboration platforms. Reporting has linked Warlock to exploitation activity involving Microsoft SharePoint, SmarterMail, SolarWinds Web Help Desk, and Gladinet CentreStack, and characterized it as a likely China-based operator. Warlock has targeted high-value organizations across sectors including government, aerospace, nuclear energy, healthcare, and other enterprise environments. Publicly claimed victims and incident reporting indicate activity against organizations in multiple countries, including China, Australia, and the United Kingdom. The group has been associated with attacks on service providers and large enterprises, and has reportedly compromised dozens of organizations within a relatively short operating period. Operationally, Warlock relies heavily on defense evasion before ransomware deployment. It has repeatedly used bring-your-own-vulnerable-driver techniques and multiple EDR-killer utilities in the same intrusion to disable endpoint protections at kernel level. HexKiller was previously assessed as closely associated with Warlock, and the group has also been linked to use of several signed vulnerable drivers to terminate security products. Reporting further indicates use of DLL sideloading chains to load vulnerable drivers and impair endpoint agents at scale. Observed Warlock tradecraft spans the full ransomware lifecycle: exploitation of exposed applications for initial access; deployment of remote management and remote access tooling for persistence and hands-on-keyboard control; credential theft using post-compromise tooling; lateral movement with administrative protocols and offensive frameworks; and data exfiltration prior to ransomware execution. Warlock operators have been observed using legitimate remote administration software, cloud services, and dual-use tooling to blend into victim environments. In at least one incident, operators deployed unattended remote-management software to maintain covert administrative access. Warlock appears to operate with a financially motivated ransomware model, including public victim claims and a leak site. The group remained operational into 2026 even after periods of reduced public posting, while continuing to expand its technical arsenal and anti-EDR capabilities.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
35 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
8 malware families attributed to this actor across reporting.
3 additional families tracked in Mallory.
6 CVEs this actor has used in observed campaigns. 6 of them exploited in the wild.
"CVE-2026-23760 is an authentication bypass flaw that could allow any user to reset the SmarterMail system administrator password by sending a specially crafted HTTP request." / "ReliaQuest said it identified activity likely linked to Warlock that involved the abuse of CVE-2026-23760 to bypass authentication and stage the ransomware payload..."
CVE-2026-24423, on the other hand, exploits a weakness in the ConnectToHub API method to achieve unauthenticated remote code execution (RCE).
"Colt had an on-premise SharePoint server that had already been backdoored (via CVE-2025-53770) in the recent mass-hack wave by the time it was patched."
CVE-2014-8361 9.3 Realtek SDK, IoT Devices, Network Equipment Warlock, Sinobi, Beast Link
CVE-2025-26399 (CVSS score: 9.8) - A deserialization of untrusted data vulnerability in the AjaxProxy component of SolarWinds Web Help Desk that could allow an attacker to run commands on the host machine.
1 more CVE tied to this actor tracked in Mallory.
8 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only for comparison of exploited technologies with Qilin.
Ransomware operators deploying Zoho Assist Unattended Agent to gain persistent, stealthy remote access without requiring active user sessions; activity was consistent with successful Warlock ransomware attacks observed by Talos.
Mentioned only as prior attribution context for the third-party EDR killer HexKiller.
Referenced because HexKiller, later included in Gentlemen's toolkit portfolio, had previously been associated with Warlock.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.