Uptime Hamster: 10d 18h 20mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza warlock

warlock

2 incidentes 2 paises 1 sectores ransomware CN Ultimo: 2026-06-29
Aliases: Storm-2603
Ver en IntelTracker → APTTrail →
Warlock is a ransomware-as-a-service (RaaS) operation that first emerged in early June 2025 on the Russian-language RAMP cybercrime forum, advertising its services to potential affiliates. This group, also tracked as GOLD SALEM and strongly associated with the China-based threat actor Storm-2603, rapidly adopted a double-extortion model to profit from its intrusions. Warlock distinguishes itself through its rapid exploitation of newly discovered zero-day vulnerabilities in Microsoft SharePoint, collectively referred to as ToolShell, and the deployment of custom Command-and-Control (C2) frameworks. The group has quickly established a global reach, exploiting enterprise vulnerabilities for high-impact extortion activities across various continents and sectors. While the Warlock name is new, some reports suggest the actors behind it may have been active since 2019, potentially engaging in both espionage and financially motivated attacks, or that the Warlock ransomware payload itself is a

Aliases del actor

Storm-2603

Actores similares

Storm-2603ransomware · 0stormousransomware · 177crimson-sandstormactor · 1Storm-1811actor · 1Storm-0501apt · 1Dust Stormapt · 1storm-cloudactor · 1unc1549-crimson-sandstormactor · 1smoke-sandstorm-cuboid-saactor · 1Storm-0324apt · 0

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
Repositorioupgithub.comWarLock
DLS / leak siteupraw.githubusercontent.comWarLock
DLS / leak siteupreliaquest.comWarLock
DLS / leak siteupwww.linkedin.comWarLock
DLS / leak siteupwww.microsoft.comWarLock
Repositoriounknowngithub.comBushidoUK ToolMatrix GroupProfiles: Warlock
Repositoriounknowngithub.comBushidoUK ToolMatrix GroupProfiles: Warlock
DLS / leak siteunknownwww.trendmicro.comBushidoUK ToolMatrix GroupProfiles: Warlock
DLS / leak siteunknownwww.sophos.comBushidoUK ToolMatrix GroupProfiles: Warlock
DLS / leak siteunknownblog.talosintelligence.comBushidoUK ToolMatrix GroupProfiles: Warlock
DLS / leak siteunknownransomware.anggipradana.comRansomware Group: warlock
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

United States (1) China (1)

Paises objetivo (SOCRadar)

United Arab EmiratesArgentinaAustriaAustraliaBulgariaBermudaBolivia, Plurinational State ofBrazilCanadaChina

Sectores atacados

Software (1)

Sectores objetivo (SOCRadar)

Construction of BuildingsFood ManufacturingOther Information ServicesMonetary Authorities-Central BankSoftware PublishersReal EstateAccommodationAir TransportationManufacturingConstruction

URLs nuevas detectadas en IntelTracker

github.com raw.githubusercontent.com ransomware.anggipradana.com