Warlock Ransomware Group
Warlock is a newly emerged, highly aggressive Ransomware-as-a-Service (RaaS) operation that first surfaced in mid-2025. It is known for its rapid expansion and use of sophisticated tactics, often targeting high-profile entities globally.
Warlock affiliates have been closely linked to exploiting zero-day vulnerabilities in public-facing enterprise applications, most notably the "ToolShell" exploit chain in unpatched Microsoft SharePoint servers, which allows for initial compromise and remote code execution.
Warlock activity has been tied to the China-based threat actor tracked by Microsoft as Storm-2603 (also known as GOLD SALEM).
Research indicates Warlock payload may be a modified variant of other well-known ransomware, such as LockBit 3.0 or a rebrand of a payload named Anylock, which is common in the fluid RaaS ecosystem.
[developing]
