Ransomware Intelligence

warlock

Ransomware group profile

68Victims
ChinaSource country
77Impact score
Also Known As
Storm-2603

Description

Warlock is a financially motivated ransomware group that emerged in June 2025, primarily operating under a Ransomware-as-a-Service model. Notably, it exploits vulnerabilities in Microsoft SharePoint for initial access and has shown rapid evolution in tactics to enhance its post-exploitation activities.

Key insights

  • Warlock leverages unpatched Microsoft SharePoint vulnerabilities for initial access, particularly exploiting the ToolShell vulnerability chain.
  • The group uses its proprietary ransomware with a distinctive .x2anylock file extension, often combined with data exfiltration efforts.
  • Warlock employs a double extortion strategy, threatening to leak stolen data publicly alongside file encryption.
  • The group utilizes advanced tactics for evasion, such as deploying vulnerable third-party drivers and executing custom malware.
  • Ties to Storm-2603 and possible connection with the Black Basta group suggest a broad network of cybercriminal activity.
  • Warlock targets a range of sectors including healthcare, finance, and public administration with significant impacts on these industries.

Threat Level & Status Breakdown

For warlock · Based on incidents in selected period

1.9threat level
Aggressiveness5/ 10
Lethality0/ 10
Criticality0.5/ 10
First seenJun 2025
Last seenNov 2025
Avg ransom
Payment rate
Statusactive
Sophistication0
Last updatedJun 2, 2026

Recent activity

Monthly attack count for warlock in the selected period

68Total attacks
20peak in Aug
13.6avg / month
↑ 6 vs first month
JunJulAugSepNov05101520

Intelligence

IOCs, YARA/Sigma rules, and related families for warlock

  1. f0ac3999d4020cd051052a0627a2056d
  2. 468121e7d6952799f92940677268937c4c5f92ed
  3. 9b04a93e05ccff94667f04bffa7af600
  4. b7703a59c39a0d2f7ef6422945aaeaaf061431af0533557246397551b8eed505
  5. db89ec570e6281934a5c5fcf7f4c8967
  6. ceec1a2df81905f68c7ebe986e378fec0805aebdc13de09a4033be48ba66da8b
  7. 54de95cc33834a2f877ba4842860af27
  8. 9e82ee5bde6b5d29281a3c280e6d1f2e
  9. 2e328297a4afd4ea2b482063e6a18ea3
  10. 79bef5da8af21f97e8d4e609389c28e0646ef81a6944e329330c716e19f33c73
  11. b16e217cdca19e00c1b68bdfb28ead53b20adeabd6edcd91542f9fbf48942877
  12. edfae1a69522f87b12c6dac3225d930e4848832e3c551ee1e7d31736bf4525ef
  13. 6ee94f6bdc4c4ed0fff621fec36c70ff093659ed
  14. 12f177290a299bae8a363f47775fb99f305bbdd56bbdfddb39595b43112f9fb7
  15. f06fe1c3e882092a23002bed3e170da7b64e6b4475acdedea1433a874b10afdf
  16. c27b725ff66fdfb11dd6487a3815d1d1eba89d61b0e919e4d06ed3ac6a74fe94
  17. 09401e712d4ffa5e497787978fe90c1557a0092b
  18. 8f58da414ec4cdad2f6ac86c19e0a806886c63cfdf1fbbb5a0713dce8a0164c5
  19. 47ec51b5f0ede1e70bd66f3f0152f9eb536d534565dbb7fcc3a05f542dbe4428
  20. 0098c79e1404b4399bf0e686d88dbf052269a302
  21. 39300863bcaad71e5d4efc9a1cae118440aa778f
  22. bc65ed919988c8e4b8f5a1cd371745456601700a
  23. 5d6b9e80e12bfc595d4d26f6afb099b3cb471dd4
  24. 3e2272b916da4be3c120d17490423230ab62c174
  25. 6bc8e3505d9f51368ddf323acb6abc49
  26. 78cd87dfa9ba0f9b533310ca98b54489
  27. 61e3bda477c87c9bdae1fa57e46b1ed03543c1ae
  28. 7cbe4243c09f299b2dbfdc10f63846541367dcef
  29. d520d06d78afcad2e03842cb8db4622d18b92739e89dfb8dadf5743f30dcd903
  30. 983b4e6edd2b289dd1a389aed908861fd8f0bf7d8e82a916ebe6d4df8642ab54
  31. 6f71d33fba02f1a6f24a3bc9bf2342b6
  32. 4147a1c7084357463b35071eab6f4525a94476b40336ebbf8a4e54eb9b51917f
  33. 7883afb713379d375b35c26d40eca326e6f73286
  34. 7310d6399683ba3eb2f695a2071e0e45891d743b
  35. 929e3fdd3068057632b52ecdfd575ab389390c852b2f4e65dc32f20c87521600
  36. 6d0cc6349a951f0b52394ad3436d1656ec5fba6a
  37. ea8c8f834523886b07d87e85e24f124391d69a738814a0f7c31132b6b712ed65
  38. ce1b9909cef820e5281618a7a0099a27a70643dc
  39. 6feb5361fd3abd3a7a733c30bfcc2b58fc774ac6aa91a468ce2e31dcffc9d4de
  40. 023d722cbbdd04e3db77de7e6e3cfeabcef21ba5b2f04c3f3a33691801dd45eb
  41. 1eb914c09c873f0a7bcf81475ab0f6bdfaccc6b63bf7e5f2dbf19295106af192
  42. 2bae4487ccb7cb14ea48947725c452ac
  43. aa0b7d4d3e1638a9c622779d27b5ee9118352b6e
  44. e75e5778e71e062ce4a7af673f0b2513854d2367fee0f01a26c0c998863bdf6e
  45. 1b5e6b1f7c46aaaaaecc49352e0e41eb
  46. a9f37104d2d89051f34e1486bc6ebff44d147e67
  47. 06142acc825e0d799d12ff0a03fd714b119c69dce868c98bb5def165b2425454
  48. a768244ca664349a6d1af84a712083c0
  49. 129eec0c999653e30a659f6a336c76d3b6ce810d459a7f860bacbc06fd556277
  50. 8f3caf8e9415da6a4cb732a9c3db4e5b
View full IOC feed500 total

TTPs & Attack Vectors

Tools, initial access, and MITRE ATT&CK techniques for warlock

Other

T1486

T1486

T1490

T1490

T1021

T1021

T1562

T1562

T1080

T1080

T1078

T1078

T1547

T1547

T1059

T1059

T1021.001

T1021.001

T1203

T1203

T1053

T1053

T1083

T1083

Victims(68)

CompanyDomainCountryIndustryStatusDiscovered
atg.czatg.czCZ Czech RepublicTechnology
Unknown
7 months ago
tein.co.jptein.co.jpJP JapanTechnology
Unknown
7 months ago
bel.quadra.rubel.quadra.ruRU RussiaProfessional Services
Unknown
7 months ago
ippm.orgippm.orgGB United KingdomOther
Unknown
7 months ago
sf.walltopia.comsf.walltopia.comUS United StatesHospitality
Unknown
7 months ago
nartis.runartis.ruRU RussiaManufacturing
Unknown
7 months ago
alphasys.boalphasys.boBO BoliviaTechnology
Unknown
7 months ago
silanosn.localsilanosn.localIT ItalyManufacturing
Unknown
7 months ago
metro.localmetro.localNA NamibiaRetail & E-Commerce
Unknown
7 months ago
miltech.localmiltech.localIS IcelandManufacturing
Unknown
7 months ago
energogroup.netenergogroup.netRU RussiaEnergy & Utilities
Unknown
7 months ago
cybervector.co.ukcybervector.co.ukGB United KingdomTechnology
Unknown
7 months ago
goldenline.comgoldenline.comPL PolandTechnology
Unknown
7 months ago
mytune.memytune.meMY MalaysiaHospitality
Unknown
7 months ago
fabrity.localfabrity.localPL PolandTechnology
Unknown
7 months ago
bengineered.com.aubengineered.com.auAU AustraliaTechnology
Unknown
7 months ago
mnpease.camnpease.caCA CanadaFinancial Services
Unknown
7 months ago
siball.netsiball.netRU RussiaTechnology
Unknown
8 months ago
chroma.com.twchroma.com.twTW TaiwanTechnology
Unknown
9 months ago
ferus-smit.homeferus-smit.homeNL NetherlandsManufacturing
Unknown
9 months ago

Page 1 of 4