Warlock Ransomware

Description Summary

The Warlock ransomware and operator(s) are believed to be attributed to Storm-2603, a China-based threat actor who is also known to have deployed LockBit ransomware. There's also a crossover between victims with Black Basta. Both are RaaS and have a long list of known and unknown affiliates. Having said that, this is possibly an affiliate (likely a cybergroup) of both of those groups. The Alliance & Association would technically be Encryptor Sharing, but this is realistically more of an "Old Affiliate" that created their own ransomware encryptor and operation.

Threat Actor

Storm-2603 / GOLD SALEM (China-based); initial access via SharePoint 'ToolShell' CVE-2025-53770/49706/49704; ASPX web shells, Mimikatz, PsExec.

Technical Indicators

Encryption Extension
.x2anylock
Encryption Algorithm
AES-256 + RSA (built on the Chaos framework); deployed via GPO for network-wide encryption
Ransom Note Name
Not publicly reported
Targeted Industries
Cross-sector (US federal, energy, telecom, education)
First Seen
July 2025
Last Seen
Active (400+ orgs)
Geographical Location
Global

MITRE ATT&CK Matrix

Tactic TTP Technique Name
Impact x 2 T1486 Data Encrypted for Impact
T1490 Inhibit System Recovery
Exfiltration x 1 T1567 Exfiltration Over Web Service (leak site)
Initial Access x 2 T1190 Exploit Public-Facing Application
T1078 Valid Accounts