Financially motivated ransomware operation tracked by Microsoft as Storm-2603 and by Sophos CTU as GOLD SALEM. Multiple vendors assess (with low-to-moderate confidence) a possible China nexus, based on TTP overlaps with Chinese state-sponsored clusters, exploitation of SharePoint vulnerabilities concurrently with Chinese state actors (Linen Typhoon, Violet Typhoon), and a willingness to target Russian and Taiwanese entities atypical for CIS-based crews. Attribution to a specific China-nexus group is unconfirmed and disputed; treat the China link as an analytic hypothesis, not established fact.
First seen
2025-03
Last active
2025-09
Motivation
Financial (ransomware extortion / double extortion); some analysts raise the possibility that ransomware serves as cover or a secondary objective alongside intelligence-gathering, given victim selection overlapping Chinese state-sponsored espionage interests.
Attribution confidence
medium
MENA targeting
Saudi Arabia, UAE
Sectors
Technology
Corpus activity · 6mo1 mention
AMJJAS
Sourced from leak-site trackers — reflects the group's claim of a victim, not a confirmed breach.
Why it mattersRansomware actor, medium confidence, documented targeting Saudi Arabia, UAE (Technology sector).
What's nextNo pipeline reports reference this actor yet — Radar mentions may still surface early signal.
No open hunts or recent alerts tracked against this actor right now.
Rows marked inferred are OSINT-extracted enrichment for actors without a MITRE Group ID — treat as analyst assessment, not authoritative ATT&CK attribution.
BYOVD: imported signed vulnerable drivers (rsndispot.sys, kl.sys, ServiceMouse.sys, renamed Baidu/Antiy/Rising drivers) to run in kernel and disable EDR.
Modified Group Policy Objects to push batch scripts that deployed ransomware enterprise-wide.
Regional co-occurrence · associated techniques
Honesty note
Regional co-occurrence is association, not prediction. These techniques appeared alongside Warlock's activity across the tracked MENA roster — a TIE-style association computed on our corpus (not CTID's model), not a prediction of the next move. Ranked by support-adjusted lift (over-representation among actors like this one vs. the roster base rate, damped when few actors back it), so neither a merely-common technique nor a tiny-sample coincidence floats to the top. A hunting lead only; never recorded as observed. ICS techniques are excluded.
Which Microsoft 365 controls protect, detect, or respond to this actor's techniques — from the CTID Mappings Explorer (technique-level). Strength: significant / partial / minimal.
protect · 7 techniques
App GovernanceT1562significantDefender for Cloud AppsT1219significantIdentity Secure ScoreT1552minimalPrivileged Identity ManagementT1136partialRole Based Access ControlT1059minimalRole Based Access ControlT1136minimalRole Based Access ControlT1484partialRole Based Access ControlT1562minimalAntimalwareT1059significantAntimalwareT1059.001significantAudit SolutionsT1552partialAudit SolutionsT1562partial
detect · 15 techniques
App GovernanceT1562significantAdvanced Threat HuntingT1552significantAdvanced Threat HuntingT1562significantDefender for Cloud AppsT1071minimalDefender for Cloud AppsT1219partialDefender for Cloud AppsT1484minimalDefender for Cloud AppsT1484.001minimalDefender for Cloud AppsT1486partialMicrosoft Defender for IdentityT1003minimalMicrosoft Defender for IdentityT1059minimalMicrosoft Defender for IdentityT1059.001minimalMicrosoft Defender for IdentityT1071minimalMicrosoft Defender for IdentityT1071.004partialMicrosoft Defender for Identity
respond · 5 techniques
Incident ResponseT1059minimalIncident ResponseT1136minimalIncident ResponseT1552minimalIncident ResponseT1562minimalZero Hour Auto PurgeT1059significantZero Hour Auto PurgeT1059.001significant
Countermeasures · D3FEND
Defensive techniques that counter Warlock's TTPs, from MITRE D3FEND. The ATT&CK↔D3FEND link is mitigation-mediated — treat these as candidate countermeasures, not prescriptions.