Skip to main content
Mallory
MalwareRansomwareUsed by 11 actorsExploits 10 CVEs

Warlock

Warlock is a ransomware family and associated ransomware operation active since at least March 2025, with public victim postings beginning in June 2025. It is linked to the threat group Warlock Group, which Sophos tracks as GOLD SALEM and Microsoft tracks as Storm-2603; Microsoft assessed Storm-2603 with moderate confidence as China-based, while Sophos said it lacked sufficient evidence to confirm that attribution. The operation has been described as a ransomware-as-a-service offering advertised on a Russian cybercrime forum, and it operates a Tor-based leak site for extortion and publication of stolen data. Reported victims span North America, Europe, South America, Latin America and the Caribbean, and Asia-Pacific, including sectors such as government, telecommunications, agriculture, energy and natural resources, and commercial enterprises.

Observed intrusion tradecraft includes exploitation of internet-facing on-premises Microsoft SharePoint vulnerabilities CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771. In these attacks, operators uploaded ASPX web shells including spinstall0.aspx and variants spinstall.aspx, spinstall1.aspx, and spinstall2.aspx; stole SharePoint ASP.NET MachineKeys; established persistence; dumped credentials with Mimikatz; moved laterally with PsExec, Impacket, and WMI; disabled Microsoft Defender via registry changes; and distributed Warlock ransomware through modified Group Policy Objects. Sophos also observed GOLD SALEM using ToolShell exploitation to deploy an ASPX web shell, downloading a Golang-based WebSockets backdoor as Sophos-UI.exe from filebin.net, and using a BYOVD technique with a vulnerable Baidu Antivirus driver renamed googleApiUtil64.sys, exploiting CVE-2024-51324, to terminate an EDR agent.

Warlock-linked activity also includes exploitation of SmarterMail vulnerabilities in 2026. Reporting states Storm-2603 exploited CVE-2026-23760, an authentication bypass allowing administrator password reset, and abused SmarterMail’s built-in Volume Mount feature to gain full system control; probing and exploitation of CVE-2026-24423, an unauthenticated RCE issue in ConnectToHub, were also reported. In these intrusions, the actor installed Velociraptor, including via an MSI payload named v4.msi hosted on Supabase, to maintain access and stage ransomware deployment. SmarterTools confirmed that the Warlock group breached its network on January 29, 2026 through an unpatched SmarterMail instance, affected about 12 Windows servers and a secondary QC data center, took over Active Directory after several days, created new users, deployed additional payloads including Velociraptor, and then attempted file encryption.

Additional reported behaviors include abuse of Velociraptor to establish a Visual Studio Code network tunnel to attacker-controlled infrastructure, use of legitimate remote administration or support tooling in some related intrusions, and deployment alongside or in proximity to other ransomware families including LockBit, Babuk, and X2anylock. Reported file-extension and note artifacts associated with Warlock activity include .xlockxlock and .x2anylock in some incidents. Published Warlock-related indicators include filenames such as IIS_Server_dll.dll, SharpHostInfo.x64.exe, xd.exe, debug_dev.js, and the path \1[5-6]\TEMPLATE\LAYOUTS\debug_dev.js; network indicators cited in reporting include 65.38.121.198, 131.226.2.6, 134.199.202.205, 104.238.159.149, 188.130.206.168, and c34718cbb4c6.ngrok-free.app.

High-confidence reporting also ties Warlock to notable incidents including attacks following SharePoint zero-day exploitation in July 2025 and the SmarterTools breach in January 2026. Public reporting states the group had reached dozens of leak-site victim listings in 2025, with one report citing 43 listings in Q3 2025 and another citing 60 victims by mid-September 2025.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

EXPLOITED CVES

Vulnerabilities exploited

10 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.

10 CVES
CVE-2025-53770ToolShell unauthenticated RCE in Microsoft SharePoint ServerExploited in the wild

The U.S. Cybersecurity and Infrastructure Security Agency warned earlier this month that remote code execution flaw - publicly known as "ToolShell" - allows unauthenticated system access and authenticated access via network spoofing. The agency said attackers can gain full access to SharePoint content, including file systems and configurations. | The computing giant published an emergency patch described by Google Cloud's Mandiant consulting chief technology officer as "uniquely urgent and drastic" (see: SharePoint Zero-Days Exploited to Unleash Warlock Ransomware).

via bank info securitybankinfosecurity.com
CVE-2024-51324Arbitrary Process Termination in Baidu Antivirus BdApiUtil DriverExploited in the wild

CTU researchers also observed GOLD SALEM bypass EDR by using the Bring Your Own Vulnerable Driver (BYOVD) technique and a vulnerable Baidu Antivirus driver renamed googleApiUtil64.sys to terminate the EDR agent. A flaw in this driver (CVE-2024-51324) allows for arbitrary processes to be terminated. | CTU™ researchers track as GOLD SALEM, has compromised networks and deployed its Warlock ransomware since March 2025.

via sophos threat researchsophos.com
CVE-2025-53771Microsoft SharePoint ToolShell path traversal spoofing vulnerabilityExploited in the wild

This exploit chain relies on using a combination of vulnerabilities CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771. | CTU™ researchers track as GOLD SALEM, has compromised networks and deployed its Warlock ransomware since March 2025.

via sophos threat researchsophos.com
CVE-2025-49706Improper authentication spoofing vulnerability in Microsoft Office SharePointExploited in the wild

This exploit chain relies on using a combination of vulnerabilities CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771. | CTU™ researchers track as GOLD SALEM, has compromised networks and deployed its Warlock ransomware since March 2025.

via sophos threat researchsophos.com
CVE-2025-49704Remote Code Execution in Microsoft Office SharePointExploited in the wild

Microsoft Security Response Center (MSRC) published a blog addressing active attacks against on-premises SharePoint servers that exploit CVE-2025-49706, a spoofing vulnerability, and CVE-2025-49704, a remote code execution vulnerability. | Microsoft has observed another China-based threat actor, tracked as Storm-2603, exploiting these vulnerabilities to deploy ransomware... Starting on July 18, 2025, Microsoft has observed Storm-2603 deploying ransomware using these vulnerabilities... Storm-2603 is then observed modifying Group Policy Objects (GPO) to distribute Warlock ransomware in compromised environments.

via microsoft generalmicrosoft.com
CVE-2025-26399Unauthenticated AjaxProxy deserialization RCE in SolarWinds Web Help DeskExploited in the wild

CVE-2025-26399 (CVSS score: 9.8) - A deserialization of untrusted data vulnerability in the AjaxProxy component of SolarWinds Web Help Desk that could allow an attacker to run commands on the host machine. The addition of CVE-2025-26399 comes in the wake of reports from Microsoft and Huntress that threat actors are exploiting security flaws in SolarWinds Web Help Desk to obtain initial access. The activity is believed to be the work of the Warlock ransomware crew.

via the hacker newsthehackernews.com
CVE-2025-6264Privilege escalation in Rapid7 Velociraptor Admin.Client.UpdateClientConfig artifactExploited in the wild

CVE‑2025‑6264 — Rapid7 Velociraptor Remote Code Execution... Exploitation Status: Actively exploited in ransomware campaigns.

via cyberthronethecyberthrone.in
CVE-2026-23760Authentication Bypass in SmarterTools SmarterMail Password Reset API

SmarterTools confirmed last week that the Warlock ransomware gang breached its network after compromising an email system... In October 2025, Halcyon cybersecurity company linked the Warlcok ransomware gang to a Chinese nation-state actor tracked as Storm-2603.

via bleeping computerbleepingcomputer.com
CVE-2026-24423Unauthenticated RCE in SmarterTools SmarterMail ConnectToHub API

SmarterTools confirmed last week that the Warlock ransomware gang breached its network after compromising an email system... In October 2025, Halcyon cybersecurity company linked the Warlcok ransomware gang to a Chinese nation-state actor tracked as Storm-2603.

via bleeping computerbleepingcomputer.com
CVE-2025-52691Unauthenticated arbitrary file upload RCE in SmarterTools SmarterMail

SmarterTools confirmed last week that the Warlock (aka Storm-2603) ransomware gang breached its network by exploiting an unpatched SmarterMail instance.

via the hacker newsthehackernews.com
THREAT ACTORS

Groups observed using it

11 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Storm-2603

CTU™ researchers track as GOLD SALEM, has compromised networks and deployed its Warlock ransomware since March 2025.

via sophos threat researchsophos.com
UAC-0238

Groups including UAC-0238 exploited exposed RDP services to push ransomware variants such as X2anylock, Warlock, and LockBit 3.0 into compromised environments.

via cyber security newscybersecuritynews.com
camofei

Warlock Ransomware Hits US Firms Exploiting SharePoint Zero-Day, Linked to China’s CamoFei APT

via security online infosecurityonline.info
warlock_group

GOLD SALEM (also known as Storm-2603) is a financially motivated cybercriminal threat group calling itself Warlock Group responsible for the distribution of the Warlock ransomware.

via secureworks threat profilessecureworks.com
cnkjasdfgd

"WarLock ransomware hit Colt Telecom, causing outages in hosting, porting, Colt Online, and Voice API since August 12."

via securityaffairssecurityaffairs.com
Warlock

"...claimed by the Warlock ransomware gang, also known as Storm-2603..."

via scworldscworld.com
ZIRCONIUM

"Storm-2603 was using the exploit to deploy Warlock and another ransomware payload, LockBit."

via symantec blogsecurity.com
Chamelgang

"Storm-2603 was using the exploit to deploy Warlock and another ransomware payload, LockBit."

via symantec blogsecurity.com
Threat Group-3390

"Storm-2603 was using the exploit to deploy Warlock and another ransomware payload, LockBit."

via symantec blogsecurity.com
Sheathminer

"Storm-2603 was using the exploit to deploy Warlock and another ransomware payload, LockBit."

via symantec blogsecurity.com
Budworm

"Storm-2603 was using the exploit to deploy Warlock and another ransomware payload, LockBit."

via symantec blogsecurity.com
MITRE ATT&CK

Techniques & procedures

4 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

3 techniques
T1078Valid AccountsEvidence1

"That vulnerability, an authentication bypass that can be used to reset admin passwords..."

T1133External Remote ServicesEvidence1

Remote Desktop Protocol remains one of the most abused entry vectors in 2025. Groups including UAC-0238 exploited exposed RDP services to push ransomware variants such as X2anylock, Warlock, and LockBit 3.0 into compromised environments.

T1190Exploit Public-Facing ApplicationEvidence1

"SmarterTools... was hacked via a vulnerability in its own product... entry point was a virtual machine that was not updated... CVE-2026-24423... an authentication bypass that can be used to reset admin passwords..."

Persistence

2 techniques
T1078Valid AccountsEvidence1

"That vulnerability, an authentication bypass that can be used to reset admin passwords..."

T1133External Remote ServicesEvidence1

Remote Desktop Protocol remains one of the most abused entry vectors in 2025. Groups including UAC-0238 exploited exposed RDP services to push ransomware variants such as X2anylock, Warlock, and LockBit 3.0 into compromised environments.

T1078Valid AccountsEvidence1

"That vulnerability, an authentication bypass that can be used to reset admin passwords..."

Stealth

1 technique
T1078Valid AccountsEvidence1

"That vulnerability, an authentication bypass that can be used to reset admin passwords..."

Impact

1 technique
T1486Data Encrypted for ImpactEvidence3
TacticImpact

Several intrusions led to the deployment of destructive wiper malware, ransomware, and long-running espionage tools designed to silently collect and exfiltrate sensitive information.

INDICATORS OF COMPROMISE

IOCs tracked for this family

21 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
5 tracked

IPs, domains, and DNS infrastructure linked to this family.

Hashes
15 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

Other
1 tracked

Other indicator types observed in public reporting.

TypeValueLatest sighting
ip.v4●●●●●●●●●●●●View more in app5 months ago
ip.v4●●●●●●●●●●●●View more in app5 months ago
hash.md5●●●●●●●●●●●●View more in app5 months ago
hash.md5●●●●●●●●●●●●View more in app5 months ago
hash.sha256●●●●●●●●●●●●View more in app5 months ago
uri●●●●●●●●●●●●View more in app5 months ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching21

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution11

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities10

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping4

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.