GOLD CRESCENT is a ransomware threat actor associated with the Warlock ransomware operation and tracked by Microsoft as Storm-2603. The group has conducted network intrusions and extortion activity since at least March 2025, publicly listing dozens of victims across North America, Europe, and South America. Victimology includes small commercial organizations, large multinational enterprises, and government entities. The actor operates a dedicated leak site and uses stolen-data publication as part of its extortion model. Observed tradecraft includes exploitation of the SharePoint ToolShell exploit chain for initial access, followed by deployment of an ASPX web shell for remote command execution. For persistence and continued access, the actor has used a Golang-based WebSockets backdoor and has also abused legitimate tooling such as Velociraptor to establish a Visual Studio Code network tunnel inside compromised environments. Defense evasion has included Bring Your Own Vulnerable Driver techniques to disable endpoint protection through abuse of a vulnerable antivirus driver. Credential theft has been observed through Mimikatz access to LSASS memory, and lateral movement has involved PsExec and Impacket. In some incidents, the actor deployed Warlock ransomware across victim environments using Group Policy Objects. The group has also maintained an underground forum presence, including solicitation for exploits affecting enterprise technologies and requests for cooperation from initial access brokers, indicating an interest in scaling access acquisition and intrusion capability. Microsoft has assessed the actor with moderate confidence as China-based, but that attribution has not been independently corroborated in the available reporting. The actor has largely avoided targeting organizations in China and Russia, though at least one Russia-based victim has been publicly listed. Known aliases include Warlock Group, GOLD SALEM, and Storm-2603.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
1 malware family attributed to this actor across reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced only as a separate ransomware operation previously affecting the same victim later listed by GOLD SALEM.
Referenced as a separate ransomware operation that previously victimized the same U.S.-based construction contractor later listed by GOLD SALEM.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.