Ransomware
Warlock GroupStorm-2603GOLD SALEM
Attribution
Financially motivated ransomware operation tracked by Microsoft as Storm-2603 and by Sophos CTU as GOLD SALEM. Multiple vendors assess (with low-to-moderate confidence) a possible China nexus, based on TTP overlaps with Chinese state-sponsored clusters, exploitation of SharePoint vulnerabilities concurrently with Chinese state actors (Linen Typhoon, Violet Typhoon), and a willingness to target Russian and Taiwanese entities atypical for CIS-based crews. Attribution to a specific China-nexus group is unconfirmed and disputed; treat the China link as an analytic hypothesis, not established fact.
Motivation
Financial (ransomware extortion / double extortion); some analysts raise the possibility that ransomware serves as cover or a secondary objective alongside intelligence-gathering, given victim selection overlapping Chinese state-sponsored espionage interests.
Attribution confidence
medium
MENA targeting
Saudi Arabia, UAE
Corpus activity · 6mo1 mention
Sourced from leak-site trackers — reflects the group's claim of a victim, not a confirmed breach.
Why it mattersRansomware actor, medium confidence, documented targeting Saudi Arabia, UAE (Technology sector).
What's nextNo pipeline reports reference this actor yet — Radar mentions may still surface early signal.
No open hunts or recent alerts tracked against this actor right now.