Uptime Hamster: 35d 15h 11mDeploy: 3 Aug 2026 06:56Updated: 2026-07-21
Logo del actor de amenaza warlock

warlock

2 incidentes 2 paises 1 sectores threat-actor CN Ultimo: 2026-06-29
Aliases: Storm-2603
Ver en IntelTracker → APTTrail →
Warlock is a ransomware-as-a-service (RaaS) operation that first emerged in early June 2025 on the Russian-language RAMP cybercrime forum, advertising its services to potential affiliates. This group, also tracked as GOLD SALEM and strongly associated with the China-based threat actor Storm-2603, rapidly adopted a double-extortion model to profit from its intrusions. Warlock distinguishes itself through its rapid exploitation of newly discovered zero-day vulnerabilities in Microsoft SharePoint, collectively referred to as ToolShell, and the deployment of custom Command-and-Control (C2) frameworks. The group has quickly established a global reach, exploiting enterprise vulnerabilities for high-impact extortion activities across various continents and sectors. While the Warlock name is new, some reports suggest the actors behind it may have been active since 2019, potentially engaging in both espionage and financially motivated attacks, or that the Warlock ransomware payload itself is a

Aliases del actor

Storm-2603

Actores similares

Storm-2603ransomware · 0stormousransomware · 177storm-cloudactor · 1unc1549-crimson-sandstormactor · 1smoke-sandstorm-cuboid-saactor · 1crimson-sandstormactor · 1Storm-1811threat-actor · 1Storm-0501threat-actor · 1Dust Stormapt · 1Storm-0324apt · 0

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
DLS / leak siteunknownransomware.anggipradana.comRansomware Group: warlock
Repositorioupgithub.comWarLock
DLS / leak siteupraw.githubusercontent.comWarLock
DLS / leak siteupreliaquest.comWarLock
DLS / leak siteupwww.linkedin.comWarLock
DLS / leak siteupwww.microsoft.comWarLock
Repositoriounknowngithub.comBushidoUK ToolMatrix GroupProfiles: Warlock
Repositoriounknowngithub.comBushidoUK ToolMatrix GroupProfiles: Warlock
DLS / leak siteunknownwww.trendmicro.comBushidoUK ToolMatrix GroupProfiles: Warlock
DLS / leak siteunknownwww.sophos.comBushidoUK ToolMatrix GroupProfiles: Warlock
DLS / leak siteunknownblog.talosintelligence.comBushidoUK ToolMatrix GroupProfiles: Warlock
DLS / onionofflineelqfbcx5nofwtqfookqml7ltx2g6q6tmddys6e25vgu3al2meim6cbqd.onionCTI.FYI
DLS / onionofflinezfytizegsze6uiswodhbaalyy5rawaytv2nzyzdkt3susbewviqqh7yd.onionCTI.FYI
DLS / onionofflineocwjy4ynmpbbzhumh2ama2vl3bc77lf5auqf7nf4k45lbmzoep2rbyid.onionCTI.FYI
DLS / oniononlinewarlockhga5iw3t54ps5iytlilf7hlvxy7kwrkidspn4qoh64s4vsuyd.onionCTI.FYI
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

China (1) United States (1)

Paises objetivo (OSINT)

United Arab EmiratesArgentinaAustriaAustraliaBulgariaBermudaBolivia, Plurinational State ofBrazilCanadaChina

Sectores atacados

Software (1)

Sectores objetivo (OSINT)

Construction of BuildingsFood ManufacturingOther Information ServicesMonetary Authorities-Central BankSoftware PublishersReal EstateAccommodationAir TransportationManufacturingConstruction

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com github.com raw.githubusercontent.com