216.73.217.22

Warlock Ransomware: Old Actor, New Tricks?

· Published 23/10/2025 15:22 · Modified 24/10/2025 09:19

Export JSON

Essential information

Published
23/10/2025 15:22
Modified
24/10/2025 09:19
Tags
2025-10-23 anylock espionage lockbit ransomware warlock
Related entities
1 intrusion sets (apt), 15 techniques (mitre), 4 malware, 11 others

Description

The , first appearing in June 2025, is linked to a China-based actor with a history dating back to 2019. It gained prominence by exploiting the ToolShell vulnerability in Microsoft SharePoint. The group, known as Storm-2603, uses multiple payloads and a custom C&C framework called ak47c2. is likely a rebrand of the older and may have connections to the retired Black Basta operation. The actors behind have been involved in diverse activities, including and cybercrime, suggesting they may be contractors. Their toolset includes defense evasion tools and the use of stolen digital certificates, linking them to earlier attacks by groups like CamoFei and ChamelGang.

External references