warlock
Ransomware group profile
Description
Warlock is a financially motivated ransomware group that emerged in June 2025, primarily operating under a Ransomware-as-a-Service model. Notably, it exploits vulnerabilities in Microsoft SharePoint for initial access and has shown rapid evolution in tactics to enhance its post-exploitation activities.
Key insights
- •Warlock leverages unpatched Microsoft SharePoint vulnerabilities for initial access, particularly exploiting the ToolShell vulnerability chain.
- •The group uses its proprietary ransomware with a distinctive .x2anylock file extension, often combined with data exfiltration efforts.
- •Warlock employs a double extortion strategy, threatening to leak stolen data publicly alongside file encryption.
- •The group utilizes advanced tactics for evasion, such as deploying vulnerable third-party drivers and executing custom malware.
- •Ties to Storm-2603 and possible connection with the Black Basta group suggest a broad network of cybercriminal activity.
- •Warlock targets a range of sectors including healthcare, finance, and public administration with significant impacts on these industries.
Threat Level & Status Breakdown
For warlock · Based on incidents in selected period
Recent activity
Monthly attack count for warlock in the selected period
Intelligence
IOCs, YARA/Sigma rules, and related families for warlock
- f0ac3999d4020cd051052a0627a2056d
- 468121e7d6952799f92940677268937c4c5f92ed
- 9b04a93e05ccff94667f04bffa7af600
- b7703a59c39a0d2f7ef6422945aaeaaf061431af0533557246397551b8eed505
- db89ec570e6281934a5c5fcf7f4c8967
- ceec1a2df81905f68c7ebe986e378fec0805aebdc13de09a4033be48ba66da8b
- 54de95cc33834a2f877ba4842860af27
- 9e82ee5bde6b5d29281a3c280e6d1f2e
- 2e328297a4afd4ea2b482063e6a18ea3
- 79bef5da8af21f97e8d4e609389c28e0646ef81a6944e329330c716e19f33c73
- b16e217cdca19e00c1b68bdfb28ead53b20adeabd6edcd91542f9fbf48942877
- edfae1a69522f87b12c6dac3225d930e4848832e3c551ee1e7d31736bf4525ef
- 6ee94f6bdc4c4ed0fff621fec36c70ff093659ed
- 12f177290a299bae8a363f47775fb99f305bbdd56bbdfddb39595b43112f9fb7
- f06fe1c3e882092a23002bed3e170da7b64e6b4475acdedea1433a874b10afdf
- c27b725ff66fdfb11dd6487a3815d1d1eba89d61b0e919e4d06ed3ac6a74fe94
- 09401e712d4ffa5e497787978fe90c1557a0092b
- 8f58da414ec4cdad2f6ac86c19e0a806886c63cfdf1fbbb5a0713dce8a0164c5
- 47ec51b5f0ede1e70bd66f3f0152f9eb536d534565dbb7fcc3a05f542dbe4428
- 0098c79e1404b4399bf0e686d88dbf052269a302
- 39300863bcaad71e5d4efc9a1cae118440aa778f
- bc65ed919988c8e4b8f5a1cd371745456601700a
- 5d6b9e80e12bfc595d4d26f6afb099b3cb471dd4
- 3e2272b916da4be3c120d17490423230ab62c174
- 6bc8e3505d9f51368ddf323acb6abc49
- 78cd87dfa9ba0f9b533310ca98b54489
- 61e3bda477c87c9bdae1fa57e46b1ed03543c1ae
- 7cbe4243c09f299b2dbfdc10f63846541367dcef
- d520d06d78afcad2e03842cb8db4622d18b92739e89dfb8dadf5743f30dcd903
- 983b4e6edd2b289dd1a389aed908861fd8f0bf7d8e82a916ebe6d4df8642ab54
- 6f71d33fba02f1a6f24a3bc9bf2342b6
- 4147a1c7084357463b35071eab6f4525a94476b40336ebbf8a4e54eb9b51917f
- 7883afb713379d375b35c26d40eca326e6f73286
- 7310d6399683ba3eb2f695a2071e0e45891d743b
- 929e3fdd3068057632b52ecdfd575ab389390c852b2f4e65dc32f20c87521600
- 6d0cc6349a951f0b52394ad3436d1656ec5fba6a
- ea8c8f834523886b07d87e85e24f124391d69a738814a0f7c31132b6b712ed65
- ce1b9909cef820e5281618a7a0099a27a70643dc
- 6feb5361fd3abd3a7a733c30bfcc2b58fc774ac6aa91a468ce2e31dcffc9d4de
- 023d722cbbdd04e3db77de7e6e3cfeabcef21ba5b2f04c3f3a33691801dd45eb
- 1eb914c09c873f0a7bcf81475ab0f6bdfaccc6b63bf7e5f2dbf19295106af192
- 2bae4487ccb7cb14ea48947725c452ac
- aa0b7d4d3e1638a9c622779d27b5ee9118352b6e
- e75e5778e71e062ce4a7af673f0b2513854d2367fee0f01a26c0c998863bdf6e
- 1b5e6b1f7c46aaaaaecc49352e0e41eb
- a9f37104d2d89051f34e1486bc6ebff44d147e67
- 06142acc825e0d799d12ff0a03fd714b119c69dce868c98bb5def165b2425454
- a768244ca664349a6d1af84a712083c0
- 129eec0c999653e30a659f6a336c76d3b6ce810d459a7f860bacbc06fd556277
- 8f3caf8e9415da6a4cb732a9c3db4e5b
TTPs & Attack Vectors
Tools, initial access, and MITRE ATT&CK techniques for warlock
T1486
T1486
T1490
T1490
T1021
T1021
T1562
T1562
T1080
T1080
T1078
T1078
T1547
T1547
T1059
T1059
T1021.001
T1021.001
T1203
T1203
T1053
T1053
T1083
T1083
Victims(68)
| Company | Domain | Country | Industry | Status | Discovered | |
|---|---|---|---|---|---|---|
| atg.cz | atg.cz | CZ Czech Republic | Technology | Unknown | 7 months ago | |
| tein.co.jp | tein.co.jp | JP Japan | Technology | Unknown | 7 months ago | |
| bel.quadra.ru | bel.quadra.ru | RU Russia | Professional Services | Unknown | 7 months ago | |
| ippm.org | ippm.org | GB United Kingdom | Other | Unknown | 7 months ago | |
| sf.walltopia.com | sf.walltopia.com | US United States | Hospitality | Unknown | 7 months ago | |
| nartis.ru | nartis.ru | RU Russia | Manufacturing | Unknown | 7 months ago | |
| alphasys.bo | alphasys.bo | BO Bolivia | Technology | Unknown | 7 months ago | |
| silanosn.local | silanosn.local | IT Italy | Manufacturing | Unknown | 7 months ago | |
| metro.local | metro.local | NA Namibia | Retail & E-Commerce | Unknown | 7 months ago | |
| miltech.local | miltech.local | IS Iceland | Manufacturing | Unknown | 7 months ago | |
| energogroup.net | energogroup.net | RU Russia | Energy & Utilities | Unknown | 7 months ago | |
| cybervector.co.uk | cybervector.co.uk | GB United Kingdom | Technology | Unknown | 7 months ago | |
| goldenline.com | goldenline.com | PL Poland | Technology | Unknown | 7 months ago | |
| mytune.me | mytune.me | MY Malaysia | Hospitality | Unknown | 7 months ago | |
| fabrity.local | fabrity.local | PL Poland | Technology | Unknown | 7 months ago | |
| bengineered.com.au | bengineered.com.au | AU Australia | Technology | Unknown | 7 months ago | |
| mnpease.ca | mnpease.ca | CA Canada | Financial Services | Unknown | 7 months ago | |
| siball.net | siball.net | RU Russia | Technology | Unknown | 8 months ago | |
| chroma.com.tw | chroma.com.tw | TW Taiwan | Technology | Unknown | 9 months ago | |
| ferus-smit.home | ferus-smit.home | NL Netherlands | Manufacturing | Unknown | 9 months ago |
Page 1 of 4
Affected countries(40)
Countries where this group has been reported to target or leak victims.