Warlock ransomware group targets global industries via RaaS affiliates
ID: 6db453db-470c-5f18-893c-eb3cf715a971
STIX ID: report--6db453db-470c-5f18-893c-eb3cf715a971
Feed Name: ThreatLocker Blog
This report profiles the Warlock ransomware RaaS operation that emerged in mid-2025, describing affiliates and active exploitation of on-premises SharePoint vulnerabilities (ToolShell CVEs 2025-49706 and 2025-49704) to gain access, deploy AV-terminating tools and AK47 C2 variants, exfiltrate sensitive data, and encrypt files using an .x2anylock extension. It includes a technical analysis of ransomware behavior, kill-switch/safety checks, IoCs (file hashes, extensions, ransom note names), and recommended mitigations using allowlisting, storage/network controls, and detection/MDR services.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
