Emerging Threat Actor: Warlock Ransomware
ID: 525b94c0-f16c-5910-bdfc-7b260046a3e9
STIX ID: report--525b94c0-f16c-5910-bdfc-7b260046a3e9
Feed Name: Halcyon Blog
The report describes the Warlock ransomware-as-a-service operation that emerged in June 2025 and rapidly exploited a chain of SharePoint zero-day vulnerabilities (the ToolShell chain: CVE-2025-49706, CVE-2025-49704, CVE-2025-53770, CVE-2025-53771) to deploy spinstall*.aspx web shells, harvest credentials with Mimikatz, move laterally via PsExec/Impacket, and deploy ransomware via GPOs; activity is tied to the China-based actor Storm-2603 and has impacted hundreds of SharePoint servers and dozens of victim organizations using double-extortion tactics.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
