MARCH 18, 2026
By 2025, the ecosystem of ransomware had become as fragmented, competitive, and dangerous as it’s ever been. Among the many emerging groups that year was Warlock Group, aka GOLD SALEM and tracked by Microsoft as Storm-2603, which gained notoriety quickly. In just a few months of operations, Warlock was exploiting zero-day vulnerabilities in Microsoft SharePoint; it had implemented custom Command-and-Control (C2) frameworks; and it had developed a leak site featuring dozens of global victims.
The rise of Warlock Group exemplifies two more substantial trends in today’s cyber threat landscape: (1) the mixing of tradecraft originating from nation-state groups with that of financially-motivated ransomware, and (2) the rapid weaponization of vulnerabilities in enterprise software.

Warlock Group is tracked under these multiple, related aliases:
Attribution remains contested. Microsoft assesses the cluster with moderate confidence to be based in China due to its clustered operational overlap with clusters associated previously with Chinese-based threat activity, while other vendors shy away from any attribution, citing competition, opportunism, etc. stressing that the group’s financial motivation – profit through ransomware extortion – could well mitigate any state sponsorship angle.
Regardless of its origins, the group’s objectives are straightforward: profit from intrusions utilizing double extortion tactics. They will encrypt victim’s environments while stealing sensitive data, which they will publish on their leak site if the ransom is not paid.
In March 2025, Warlock Group made headlines when it exploited a series of critical Microsoft SharePoint vulnerabilities collectively known as “ToolShell” (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, CVE-2025-53771).
This uncritical exploitation exemplifies an increased trend of adversaries rushing to weaponize recently disclosed vulnerabilities with widely deployed enterprise software.
Warlock was utilizing custom and off-the-shelf tools:
The combination of custom tools and commoditized tools reveals the group’s adaptability and desire to make detection more complex.
After establishing a foothold, Warlock used:
This toolkit mirrors operations of established ransomware, demonstrating Warlock’s robust maturity.
Warlock’s operations end in the execution of its ransomware that encrypts victim systems and exfiltrates sensitive data at the same time. Victims are then publicly identified on the group’s dark web leak site, previously known as Data Leak 101, and pressure campaigns escalate if the ransom is not paid.

The Warlock group has exhibited broad target patterns that do not narrow in on a single sector. As of mid-September 2025, the group claimed just under 60 victims across diverse target sectors, to include:
Geographically, Warlock has not limited its operations to any of North America, Europe, and South America, but has also exhibited activity in the Asia-Pacific (APAC) and Latin American regions.
This targeting pattern is consistent with organized crime, financially motivated ransomware groups that are less concerned with target sector alignment and more concerned with opportunity.
The evolution of Warlock Group is characterized by speed:
Looking ahead, a number of developments are anticipated:
The emergence of Warlock Group (GOLD SALEM / Storm-2603) in 2025 highlights how quickly new players in the ransomware economy can emerge and disrupt the cyber threat landscape. Through rapid weaponization of SharePoint vulnerabilities, using custom tooling like AK47 C2, and adopting aggressive double-extortion methodologies, Warlock has quickly established themselves as a high-risk potential actor with a global reach.
For defenders, key takeaways include:
The trajectory Warlock takes as they ramp their operations will challenge enterprises’ resilience against a new wave of ransomware groups; a group that mixes a state-like common tradecraft with relentless financial pressure to meet their own goals.
You can download and review the sheet for all the details!

Take control of your digital security with an exclusive demo of our powerful threat management platform.