The Warlock ransomware and operator(s) are believed to be attributed to Storm-2603, a China-based threat actor who is also known to have deployed LockBit ransomware. There's also a crossover between victims with Black Basta. Both are RaaS and have a long list of known and unknown affiliates. Having said that, this is possibly an affiliate (likely a cybergroup) of both of those groups. The Alliance & Association would technically be Encryptor Sharing, but this is realistically more of an "Old Affiliate" that created their own ransomware encryptor and operation. Known victims: 78 2 ransom note(s) on file
Objectives
Executive Summary
Warlock is a medium-sophisticated ransomware-related threat actor, likely operating as an affiliate group linked to Storm-2603, LockBit, and Black Basta ransomware operations. The group primarily focuses on organizational gain through financial exploitation using ransomware deployment. Observed activity dates back to April 2025, with known victims reaching 78 instances and associated ransom notes indicating operational maturity.
Goals & Targeting
Warlock's primary objective is to generate financial profit through the distribution of ransomware. The group likely targets organizations with valuable data that can be encrypted and ransomed. While there is no specific evidence of targeting within particular sectors or countries, their association with broader RaaS operations suggests they may participate in campaigns against a variety of industries lacking robust cybersecurity measures. Their victims (78 known instances) indicate a broad operational scope, potentially focusing on mid-sized businesses that are less prepared for cyberattacks but have sufficient data value to justify the effort.
Enhanced Description
Warlock represents a notable threat in the ransomware landscape, operating as either an independent affiliate or subgroup linked to larger ransomware-as-a-service (RaaS) operations. The actor's activities suggest a focus on financial gain through targeted ransomware deployments, leveraging their affiliation with established groups like Storm-2603 and LockBit. This dual association indicates potential access to RaaS tools and operational frameworks for executing campaigns. While the group has demonstrated campaign activity since April 2025, specific targeting patterns remain unclear. The actor's operations appear to involve standard ransomware deployment techniques, including phishing and encryption of victim systems. Despite its criminal focus on financial gain, the Warlock threat actor does not explicitly align with a known nation-state agenda, making it a purely financially motivated group.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Campaigns & Victims
Warlock's campaign patterns are consistent with affiliate activity within broader RaaS networks. Known victims suggest a focus on organizational targets that may not have stringent cybersecurity measures. Despite operational activity since April 2025, specific details about campaign targeting or unique TTPs are limited. Notable past operations include the deployment of LockBit ransomware in conjunction with other groups, indicating shared operational frameworks.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in this assessment is moderate due to limited available data on specific TTPs and targeting patterns. Known victim counts and associated hashes provide some insight into operational capacity but remain insufficient to fully detail the group's capabilities or long-term goals.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
2
IOCs
0
Observed Data
0
Tactics