Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
MalwareRansomwareUsed by 11 actorsExploits 10 CVEs

Warlock

Warlock is a ransomware family and associated extortion operation active since at least March 2025, first publicly advertised in June 2025 and tracked by Sophos CTU as GOLD SALEM and by Microsoft as Storm-2603. It has compromised networks across North America, Europe, South America, Latin America/Caribbean, and Asia-Pacific, with victims including small businesses, large multinationals, government entities, telecommunications, agriculture, energy and natural resources, and other sectors. Multiple sources describe the actor as financially motivated; Microsoft assessed Storm-2603 with moderate confidence as China-based, while Sophos stated it lacked sufficient evidence to confirm that attribution.

Observed initial access includes exploitation of internet-facing Microsoft SharePoint Server via the ToolShell exploit chain and related vulnerabilities CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771, as well as exploitation of SmarterMail vulnerabilities including CVE-2026-23760 and CVE-2026-24423. Warlock-linked intrusions have also been associated with exploitation of SolarWinds Web Help Desk (CVE-2025-40551) and Gladinet CentreStack (CVE-2025-14611), and some reporting notes deployment via exposed RDP services. In SharePoint cases, attackers uploaded ASPX web shells such as spinstall0.aspx and variants spinstall.aspx, spinstall1.aspx, and spinstall2.aspx, executed commands via w3wp.exe/cmd.exe, stole SharePoint ASP.NET MachineKey material, and established persistence through web shells, scheduled tasks, and IIS component manipulation.

Post-compromise tradecraft includes credential theft with Mimikatz against LSASS, lateral movement with PsExec, Impacket, WMI, PowerShell Remoting, OpenSSH, Radmin, TightVNC, and Cobalt Strike, and ransomware distribution via modified Group Policy Objects. Warlock operators have repeatedly abused legitimate tools for persistence and access, notably Velociraptor, including installation of older vulnerable versions and use of Velociraptor to establish a Visual Studio Code tunnel. Additional observed tooling across Warlock-linked intrusions includes Everything.exe, SecurityCheck, Veeam-Get-Creds, Cloudflared, RClone, MinIO, Azure Blob Storage, Supabase, Catbox[.]moe, msiexec, and RDP Patcher.

Defense evasion is a prominent feature of Warlock activity. Observed intrusions used Bring Your Own Vulnerable Driver techniques to disable endpoint protections, including a vulnerable Baidu Antivirus driver renamed googleApiUtil64.sys exploiting CVE-2024-51324 to terminate EDR processes. Reporting also links Warlock affiliates to an msimg32.dll sideloading chain that loads signed vulnerable drivers rwdrv.sys and hlpdrv.sys to kill endpoint agents. Other BYOVD-related components observed in Warlock-linked intrusions include Antiy System In-Depth Analysis Toolkit driver, NsecSoft driver, Rising Antivirus driver, and VMTools AV Killer.

Warlock operates a Tor-based leak site and uses data theft and extortion in addition to encryption. Victim postings began in June 2025; one report states the group reached 43 total listings in Q3 2025, while Sophos reported 60 victims listed through mid-September 2025 and publication of stolen data from a subset of those victims. Some incidents and reporting emphasize data exfiltration and leak-site publication as part of the operation. Known indicators and artifacts directly mentioned in reporting include the web shell filenames above; files such as IIS_Server_dll.dll, SharpHostInfo.x64.exe, xd.exe, and debug_dev.js; the path \1[5-6]\TEMPLATE\LAYOUTS\debug_dev.js; IPs 65.38.121[.]198, 131.226.2.6, 134.199.202.205, 104.238.159.149, and 188.130.206.168; the host c34718cbb4c6.ngrok-free.app; and in SmarterMail-related activity, download of a malicious MSI named v4.msi from Supabase and a Golang-based WebSockets backdoor downloaded as c:\users\public\Sophos\Sophos-UI.exe from filebin.net.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

EXPLOITED CVES

Vulnerabilities exploited

10 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.

10 CVES
CVE-2025-53770ToolShell RCE in Microsoft SharePoint Server

This is the list of vulnerabilities that have been observed during intrusions that lead to WarLock ransomware deployment or data exfiltration and leaks published to WarLock's Tor Site.

via github webgithub.com
CVE-2025-49704Microsoft SharePoint Server remote code execution (ToolShell component)Exploited in the wild

SharePoint Server CVE-2025-49706, CVE-2025-49704 ("ToolShell") Storm-2603 (Warlock) ... disrupting active exploitation of on-premises SharePoint vulnerabilities | This is the list of vulnerabilities that have been observed during intrusions that lead to WarLock ransomware deployment or data exfiltration and leaks published to WarLock's Tor Site.

via github webgithub.com
CVE-2026-23760Authentication Bypass in SmarterTools SmarterMail Password Reset APIExploited in the wild

SmarterMail CVE-2026-23760 Storm-2603 (Warlock) ... observed during intrusions that lead to WarLock ransomware deployment or data exfiltration | This is the list of vulnerabilities that have been observed during intrusions that lead to WarLock ransomware deployment or data exfiltration and leaks published to WarLock's Tor Site.

via github webgithub.com
CVE-2025-49706Microsoft SharePoint Server improper authentication spoofing vulnerability (ToolShell component)Exploited in the wild

SharePoint Server CVE-2025-49706, CVE-2025-49704 ("ToolShell") Storm-2603 (Warlock) ... disrupting active exploitation of on-premises SharePoint vulnerabilities | This is the list of vulnerabilities that have been observed during intrusions that lead to WarLock ransomware deployment or data exfiltration and leaks published to WarLock's Tor Site.

via github webgithub.com
CVE-2025-14611Unauthenticated LFI in Gladinet CentreStack and Triofox via Hardcoded AES KeysExploited in the wild

Gladinet CentreStack CVE-2025-14611 Storm-2603 (Warlock) ... observed during intrusions that lead to WarLock ransomware deployment or data exfiltration | This is the list of vulnerabilities that have been observed during intrusions that lead to WarLock ransomware deployment or data exfiltration and leaks published to WarLock's Tor Site.

via github webgithub.com
CVE-2025-40551Unauthenticated RCE in SolarWinds Web Help Desk DeserializationExploited in the wild

SolarWinds Web Help Desk CVE-2025-40551 Storm-2603 (Warlock) ... observed during intrusions that lead to WarLock ransomware deployment or data exfiltration | This is the list of vulnerabilities that have been observed during intrusions that lead to WarLock ransomware deployment or data exfiltration and leaks published to WarLock's Tor Site.

via github webgithub.com
CVE-2025-6264Privilege Escalation in Rapid7 Velociraptor Admin.Client.UpdateClientConfig ArtifactExploited in the wild

The version of Velociraptor observed in this incident was outdated (version 0.73.4.0) and exposed to a privilege escalation vulnerability (CVE-2025-6264), which may have been leveraged for persistence as this vulnerability can lead to arbitrary command execution and endpoint takeover.

via talosintelligence otherblog.talosintelligence.com
CVE-2024-51324Arbitrary Process Termination in Baidu Antivirus BdApiUtil DriverExploited in the wild

CTU researchers also observed GOLD SALEM bypass EDR by using the Bring Your Own Vulnerable Driver (BYOVD) technique and a vulnerable Baidu Antivirus driver renamed googleApiUtil64.sys to terminate the EDR agent. A flaw in this driver (CVE-2024-51324) allows for arbitrary processes to be terminated.

via sophos threat researchnews.sophos.com
CVE-2025-53771SharePoint ToolShell authentication bypass / spoofing vulnerabilityExploited in the wild

In late July, CTU researchers analyzed an incident in which GOLD SALEM used the ToolShell exploit chain against SharePoint servers for initial access. This exploit chain relies on using a combination of vulnerabilities CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771.

via sophos threat researchnews.sophos.com
CVE-2025-26399Unauthenticated AjaxProxy Deserialization RCE in SolarWinds Web Help DeskExploited in the wild

CVE-2025-26399 (CVSS score: 9.8) - A deserialization of untrusted data vulnerability in the AjaxProxy component of SolarWinds Web Help Desk that could allow an attacker to run commands on the host machine. The addition of CVE-2025-26399 comes in the wake of reports from Microsoft and Huntress that threat actors are exploiting security flaws in SolarWinds Web Help Desk to obtain initial access. The activity is believed to be the work of the Warlock ransomware crew.

via the hacker newsthehackernews.com
THREAT ACTORS

Groups observed using it

11 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Storm-2603

This is the list of vulnerabilities that have been observed during intrusions that lead to WarLock ransomware deployment or data exfiltration and leaks published to WarLock's Tor Site.

via github webgithub.com
UAC-0238

Groups including UAC-0238 exploited exposed RDP services to push ransomware variants such as X2anylock, Warlock, and LockBit 3.0 into compromised environments.

via cyber security newscybersecuritynews.com
camofei

Warlock Ransomware Hits US Firms Exploiting SharePoint Zero-Day, Linked to China’s CamoFei APT

via security online infosecurityonline.info
warlock_group

GOLD SALEM (also known as Storm-2603) is a financially motivated cybercriminal threat group calling itself Warlock Group responsible for the distribution of the Warlock ransomware.

via secureworks threat profilessecureworks.com
cnkjasdfgd

"WarLock ransomware hit Colt Telecom, causing outages in hosting, porting, Colt Online, and Voice API since August 12."

via securityaffairssecurityaffairs.com
Warlock

"...claimed by the Warlock ransomware gang, also known as Storm-2603..."

via scworldscworld.com
MITRE ATT&CK

Techniques & procedures

4 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

3 techniques
T1078Valid AccountsEvidence1

"That vulnerability, an authentication bypass that can be used to reset admin passwords..."

T1133External Remote ServicesEvidence1

Remote Desktop Protocol remains one of the most abused entry vectors in 2025. Groups including UAC-0238 exploited exposed RDP services to push ransomware variants such as X2anylock, Warlock, and LockBit 3.0 into compromised environments.

T1190Exploit Public-Facing ApplicationEvidence2

Threat actors predominately exploited public-facing applications for initial access this quarter... Almost 40 percent of all engagements involved ToolShell activity... attackers began actively exploiting two path traversal vulnerabilities affecting on-premises SharePoint servers... resulting in unauthenticated remote code execution.

Persistence

2 techniques
T1078Valid AccountsEvidence1

"That vulnerability, an authentication bypass that can be used to reset admin passwords..."

T1133External Remote ServicesEvidence1

Remote Desktop Protocol remains one of the most abused entry vectors in 2025. Groups including UAC-0238 exploited exposed RDP services to push ransomware variants such as X2anylock, Warlock, and LockBit 3.0 into compromised environments.

Privilege Escalation

1 technique
T1078Valid AccountsEvidence1

"That vulnerability, an authentication bypass that can be used to reset admin passwords..."

Stealth

1 technique
T1078Valid AccountsEvidence1

"That vulnerability, an authentication bypass that can be used to reset admin passwords..."

Impact

1 technique
T1486Data Encrypted for ImpactEvidence4

T1486 Data Encrypted for Impact Adversaries may use ransomware to encrypt data on a target system... Talos IR responded to Warlock, Babuk, and Kraken ransomware variants for the first time, while also responding to previously seen families Qilin and LockBit.

INDICATORS OF COMPROMISE

IOCs tracked for this family

22 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
6 tracked

IPs, domains, and DNS infrastructure linked to this family.

Hashes
15 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

Other
1 tracked

Other indicator types observed in public reporting.

TypeValueLatest sighting
domain●●●●●●●●●●●●View more in app2 months ago
ip.v4●●●●●●●●●●●●View more in app6 months ago
ip.v4●●●●●●●●●●●●View more in app6 months ago
hash.md5●●●●●●●●●●●●View more in app6 months ago
hash.md5●●●●●●●●●●●●View more in app6 months ago
hash.sha256●●●●●●●●●●●●View more in app6 months ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching22

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution11

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities10

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping4

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.