Sourced from leak-site trackers — reflects the group's claim of a victim, not a confirmed breach.
Warlock (aka Warlock Group / Storm-2603 / GOLD SALEM) is a ransomware operation that first surfaced in early-to-mid 2025 and gained global prominence in July 2025 for weaponizing the Microsoft on-premises SharePoint 'ToolShell' exploit chain (CVE-2025-53770 / CVE-2025-49706, part of a broader set including CVE-2025-49704 and CVE-2025-53771) to achieve mass, unauthenticated initial access. The Warlock encryptor is assessed to be derived from the leaked LockBit 3.0 (Black) builder, and operators have deployed a mix of Warlock, LockBit, and Babuk (against VMware ESXi) across intrusions. Victims are named on a Tor-based 'Warlock Group' leak site.
Warlock ransomware activity was first observed by Sophos as early as March 2025, with the operation gaining widespread attention in July 2025 when researchers observed operators deploying it following exploitation of the SharePoint 'ToolShell' zero-day chain (CVE-2025-53770, a CVSS 9.8 deserialization RCE, chained with the CVE-2025-49706 spoofing/auth-bypass flaw, alongside CVE-2025-49704 and CVE-2025-53771). On 22 July 2025 Microsoft published that it tracks a subset of this SharePoint exploitation activity as Storm-2603, a financially motivated actor observed deploying Warlock and LockBit ransomware; Microsoft and others also noted a separate custom toolkit ('Project AK47'). Sophos CTU tracks the same operation as GOLD SALEM and documented a toolset including LSASS/Mimikatz credential access, BYOVD driver abuse, DLL side-loading, VS Code tunnel and Cloudflared C2, MinIO client exfiltration, and abuse of Velociraptor. Tooling and leak-site infrastructure overlaps link Warlock, LockBit, and Babuk deployments (shared contacts, a 'wlteaml' affiliate qTox ID in ransom notes), suggesting cohesive command-and-control rather than opportunistic reuse. Vendors assess a possible China nexus with low confidence based on SharePoint-exploit overlap with Chinese state clusters and targeting of Russian/Taiwanese entities. Primary claimed victims per leak-site data concentrate in the United States, United Kingdom, Japan, India, and France, spanning IT, telecommunications, financial services, manufacturing, industrial, government, energy, and agriculture. As of Sophos' September 2025 reporting the operation remained active and was assessed to run as a largely private (non-affiliate) operation, though it solicited initial access brokers on the RAMP forum in June 2025.
MENA relevance: Warlock's leak site lists a Saudi Arabian victim (kmssa.net, 2025-09-16) and a UAE victim (wfd2027uae.ae, 2025-08-17), so the Saudi Arabia and UAE country tags reflect genuine leak-site claims — neither independently confirmed as a successful breach. Warlock's overall victimology is global (US/Europe/Asia) rather than MENA-focused.
+5 more relationships — see the relationships browser.
These entities are frequently mentioned together in source material; co-occurrence is not a verified relationship.