logo

Emerging Threat Actor: Warlock Ransomware

ID: 525b94c0-f16c-5910-bdfc-7b260046a3e9

STIX ID: report--525b94c0-f16c-5910-bdfc-7b260046a3e9

Feed Name: Halcyon Blog

Threat Score
90/100

Date Published: 2025-07-25

Date Updated: 2026-04-28

...
...

The report describes the Warlock ransomware-as-a-service operation that emerged in June 2025 and rapidly exploited a chain of SharePoint zero-day vulnerabilities (the ToolShell chain: CVE-2025-49706, CVE-2025-49704, CVE-2025-53770, CVE-2025-53771) to deploy spinstall*.aspx web shells, harvest credentials with Mimikatz, move laterally via PsExec/Impacket, and deploy ransomware via GPOs; activity is tied to the China-based actor Storm-2603 and has impacted hundreds of SharePoint servers and dozens of victim organizations using double-extortion tactics.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.