logo

Warlock Group: The Rise of GOLD SALEM (Storm-2603) in 2025’s Ransomware Landscape

ID: 3db369f9-86c8-52bc-ab1b-a38288cdd489

STIX ID: report--3db369f9-86c8-52bc-ab1b-a38288cdd489

Feed Name: Brandefense Blog

Threat Score
80/100

Date Published: 2026-03-18

Date Updated: 2026-04-27

Author: BRANDEFENSE

...
...

**Executive Summary:** This report profiles Warlock Group (GOLD SALEM / Storm-2603), an emerging financially motivated ransomware actor that rapidly weaponized multiple Microsoft SharePoint zero-days (ToolShell CVEs) in 2025 to gain remote code execution, deploy ASPX web shells, exfiltrate data and execute double-extortion across roughly 60 victims worldwide; the group leverages a mix of custom tooling (AK47 C2), legitimate tools abused for persistence and access, and established post-exploitation techniques like Mimikatz, PsExec, and GPO-driven deployments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.