Key judgments
- High confidenceWarlock sells first and leaks second. Twenty-seven of the 78 leak-site listings in our collection say the data went to “other buyers (not victims)”; the operators publish only when no one pays and no one buys.
- High confidenceThe leak site has stopped tracking Warlock’s tempo. Its most recent listing is dated 26 January 2026, yet the group breached SmarterTools three days later and a critical-infrastructure operator in July.
- High confidenceDefenders had days, not minutes. In the July intrusion at least four distinct, detectable steps came before protection was switched off on 31 July — after which the estate fell in about two hours.
- Moderate confidenceInitial access follows exposure more than sector. SharePoint and SmarterMail were both reached through unpatched internet-facing servers, and the leak site lists victims in at least ten countries. Symantec’s 2026 cluster of Portuguese- and Spanish-speaking victims could still reflect deliberate tasking.
- No assessmentWe have no independent basis to go beyond Microsoft’s moderate-confidence view that Storm-2603 is China-based, and we make no judgment on state direction.
- from the first web shell to ransomware
- 9 days
- hosts with protection disabled in about two hours
- ≥ 40
- leak-site listings in our collection, 27 marked as sold
- 78
- new listings since 26 January 2026, while the intrusions continued
- 0
On 1 October 2026, Symantec and Carbon Black published the most detailed account yet of a Warlock intrusion: a critical-infrastructure operator whose SharePoint servers were compromised on 22 July and whose estate was running ransomware nine days later. BleepingComputer carried the story the next day. This analysis adds what those reports do not have — the group’s own leak-site record, the underground forums that track it, and FireIntel’s actor profile — and turns the July chronology into an ATT&CK mapping, hunting queries and machine-readable indicators.
| Status | Finding | Source |
|---|---|---|
| Observed | A web shell on 22 July; an AV/EDR killer on at least 40 hosts and Warlock on at least 33 by 31 July. | Symantec / Carbon Black telemetry, one intrusion |
| Observed | 78 leak-site listings dated by the site between 28 July 2025 and 26 January 2026; 27 marked as sold. | FireIntel DDW Advance collection |
| Observed | A SmarterMail authentication bypass used to stage Velociraptor ahead of Warlock, intercepted before encryption. | ReliaQuest, February 2026 |
| Assessed | SharePoint exploitation was the July entry route; Longlegs is the actor Microsoft tracks as Storm-2603. | Symantec; Microsoft |
| Unknown | The exact 2026 entry CVE, the July case’s driver, the victims’ identities, service impact and any ransom outcome. | Not established in the primary report |
Nine days, host by host
The first recorded malicious act came on 22 July 2026, when PowerShell wrote a web shell named layout2sp.aspx into the SharePoint LAYOUTS directory. The group writes its shell into the folders of several SharePoint versions at once, so it runs whichever version is installed; its job is to harvest the farm’s ASP.NET machine keys, which let the attackers forge a validly signed payload and run code inside the SharePoint application pool.
- Intrusion activity
- Protection disabled, ransomware deployed
- 22 Jul · SharePoint server 1
PowerShell writes the layout2sp.aspx web shell into the SharePoint LAYOUTS directory.
- 24 Jul · SharePoint server 2
Domain reconnaissance (net user /domain, whoami); staging files deleted; ssvagent.exe and logger.exe staged for DLL side-loading.
- 24 Jul · SharePoint server 1
The SharePoint worker drops a doexe.exe / doexeloc.dll side-loading pair and runs nltest /domain_trusts. The pair is still running on 30–31 July.
- 27 Jul · SharePoint server 2
Out-of-band canary: a request to an oastify.com subdomain that embeds the victim’s own domain name.
- 28 Jul, morning · SharePoint server 2
The attackers return to re-test the web shell.
- 28 Jul, afternoon · SharePoint servers 1 and 2
System.Workflow.ComponentModel is loaded repeatedly — the deserialization gadget that turns a forged, machine-key-signed __VIEWSTATE into code execution.
- 28 Jul · SharePoint server 2
Three MSI packages pulled from catbox.moe and Wasabi storage within about 90 minutes.
- 28–29 Jul · Hosts 3, 4 and 5
Domain account SPSEPRDSetup — named to look like a SharePoint setup account — repeatedly added to local Administrators.
- 29 Jul, evening · Host 4
VS Code Insiders installed as a tunnel service from C:\Windows\debug — remote access relayed through Microsoft infrastructure.
- 29 Jul, evening · SharePoint server 2
NetExec runs Active Directory enumeration, password spraying and remote command execution.
- 31 Jul, early hours · ≥ 40 hosts
a.exe, an AV/EDR killer copied from an internal share, runs across the estate in about two hours.
- 31 Jul · ≥ 33 hosts
run.exe and rune.exe launch from the SYSVOL scripts folder with the note “how to restore your files.txt”; three hosts show DFS Replication as the delivering parent.
The pace is patient, then sudden. Reconnaissance and DLL side-loading on 24 July were followed by two silent days. On 27 July an out-of-band request to oastify.com — Burp Collaborator, with the victim’s own domain baked into the subdomain — confirmed that injected code had run. On 28 July a deserialization gadget turned a forged __VIEWSTATE into code execution, and three MSI packages arrived from public file hosts within ninety minutes. Over the next day a look-alike account, SPSEPRDSetup, joined local Administrators on three more hosts; VS Code Insiders was installed as a tunnel service; and NetExec mapped Active Directory and sprayed passwords.
Then, in the early hours of 31 July, an AV/EDR killer copied from an internal share ran on at least 40 hosts in about two hours, and Warlock — run.exe, rune.exe and a note called “how to restore your files.txt” — appeared on at least 33. The payload had been staged in SYSVOL, which replicates to every domain controller: on three hosts the DFS Replication service itself was recorded delivering it.
What the dark web shows
We queried FireIntel’s DDW Advance collection for Warlock across ransomware leak sites and underground forums on 3 October 2026. The leak-site search returns 78 listings. Each record carries the leak site’s own date for the listing separately from the date it was collected, and we checked both: the listings are dated 28 July 2025 to 26 January 2026, while collection ran well into 2026. In every capture below, victim names are covered with fixed-width bars so that not even their length gives anything away; a domain suffix such as .ru or .local is left visible where it carries analytic value, and onion addresses are withheld.

Read the listings rather than counting them and the operators’ business model surfaces. Each carries a short status line written by the operators themselves, and four kinds recur:
- “The data has been bought by other buyers (not victims)” — 25 listings, plus two worded “purchased by other buyers”: 27 sales in all, every one dated July or August 2025.
- “The customer has not paid, and there are no other buyers within the validity period” — the data is then published for anyone to take. Two listings.
- Partial leaks offered as samples, with the full set “to be purchased separately” — one of them advertised as an auction of a million documents.
- The rest give only a data volume or “all data”, with no status at all.

Sophos counted the same number of sales, 27, by mid-September 2025. Neither collection names the buyers, so we cannot confirm the two counts cover identical listings, but the agreement is strong. The more telling signal is that the sales stop after August: either buyers dried up or the operators stopped advertising sales in public. What the status lines do show is the leverage. A victim who refuses to pay does not get its data back unpublished — it goes to the highest bidder or, failing one, to everyone.
Two smaller details deserve attention. Six listings are named after internal Active Directory domains ending in .local or .home rather than public websites — a sign the operators named those victims from inside the network, most likely from a domain controller. And the public domains span at least ten country codes: Australia, Bolivia, Canada, Czechia, Japan, Russia, Taiwan, the UAE, the United Kingdom and the United States. That breadth matches the geography researchers reported in 2025; the 2026 cluster of Portuguese- and Spanish-speaking victims that Symantec describes is not visible on a leak site that has been silent since January.
What the forums say
Underground forums keep their own score. On 31 January 2026, a user on a forum presenting itself as a relaunch of XSS answered a question about which ransomware groups were still active with a tracker table pasted as plain text: each group’s first and last victim, its victim counts over 7, 30 and 90 days, and whether its site was up. We have set the relevant rows out below.
| Group | First victim | Last victim | 7 days | 30 days | 90 days | Site |
|---|---|---|---|---|---|---|
| clop | 2020-03-13 | 2026-01-25 | 43 | 46 | 145 | Online |
| safepay | 2023-11-10 | 2026-01-26 | 7 | 11 | 93 | Online |
| lockbit5 | 2024-08-17 | 2026-01-21 | 0 | 7 | 79 | Online |
| dragonforce | 2022-10-20 | 2026-01-24 | 0 | 8 | 67 | Online |
| play | 2022-11-26 | 2026-01-26 | 7 | 19 | 64 | Online |
| everest | 2021-09-09 | 2026-01-21 | 0 | 21 | 47 | Online |
| medusa | 2023-01-11 | 2026-01-04 | 0 | 1 | 17 | Online |
| warlock | 2025-04-02 | 2025-11-06 | 0 | 0 | 8 | Online |
| lockbit3 | 2021-12-26 | 2025-12-05 | 0 | 0 | 1 | Online |
Group names and figures are the tracker’s own, transcribed from the post; it does not say how it counts victims. Rows are selected for comparison from a list of dozens of groups.

By the tracker’s numbers, Warlock was a small operator at the end of January: eight victims in 90 days and none in the last 30, against 145 for Clop and 79 for LockBit 5. But the tracker had missed something. It puts Warlock’s last victim at 6 November 2025, while the leak site itself dated 17 listings in January 2026, the latest on 26 January — five days before the post. Secondary trackers lag the sites they count. Its first-victim date, 2 April 2025, two months before Warlock’s public debut, is a second reason to treat it as a lead rather than a record.
Eighteen months of Warlock activity
- Leak-site entries in FireIntel’s collection
- Public reporting
- Documented intrusion
- 22 Apr 2025 · Unit 42
An account named “wlteaml” is registered on LockBit 3.0’s affiliate panel; it shares the Tox ID later embedded in AK47 ransom notes.
- 10 Jun 2025 · Sophos
Warlock appears on the RAMP forum seeking exploits and EDR killers; its first leak site goes online and drops offline a day later.
- 18 Jul 2025 · Microsoft
Storm-2603 begins deploying ransomware through the ToolShell SharePoint zero-days. Our first leak-site entry follows ten days later.
- 16 Sep 2025 · Sophos
60 victims listed; 27 marked as sold to private buyers rather than published.
- Jan 2026 · Trend Micro
A SharePoint intrusion leads to Cobalt Strike, Velociraptor, a Cloudflare tunnel and a new BYOVD driver before Warlock is pushed by Group Policy.
- 29 Jan 2026 · SmarterTools
Warlock breaches the mail-software vendor SmarterTools itself, through a forgotten, unpatched SmarterMail virtual machine.
- Feb 2026 · ReliaQuest
Storm-2603 chains a SmarterMail authentication bypass (CVE-2026-23760) with the Volume Mount feature to install Velociraptor — Warlock staging, caught before encryption.
- 14 Jul 2026 · CISA
CISA urges SharePoint hardening after three newly exploited vulnerabilities.
- 22–31 Jul 2026 · Symantec
The critical-infrastructure intrusion charted above: web shell to Warlock in nine days.
- 1 Oct 2026 · Symantec
Four recent victims disclosed: a water utility, a telecom operator, a regional government body and a university.
Laid end to end, the record shows an operation that went public fast. Warlock announced itself in June 2025, was exploiting the ToolShell zero-days within six weeks, and had a working leak site by late July. Our first listing is dated 28 July 2025; by the end of September there were 61, against the 60 that Sophos counted by mid-September.
Then the record thins. Our collection holds no listings dated October to December 2025, although the forum tracker recorded a Warlock victim on 6 November — so this is leak-site downtime or a gap in collection, not a proven pause. Seventeen listings are dated January 2026, and none since. The intrusions did not stop: Trend Micro documented one in January 2026, ReliaQuest another in February, Symantec the July case. Whatever the reason — new infrastructure, more private sales, or victims settling quietly — the leak site is no longer a reliable gauge of Warlock’s tempo.
Not only SharePoint
The front door is whichever internet-facing Windows application is behind on patches. On 29 January 2026, Warlock breached SmarterTools, the company that makes the SmarterMail mail server, through a SmarterMail virtual machine an employee had set up and nobody was updating. On 9 February, ReliaQuest attributed SmarterMail exploitation it had observed to Storm-2603 with moderate-to-high confidence: an authentication bypass, CVE-2026-23760, chained with the product’s own Volume Mount feature to run commands as the mail service, pull an MSI from Supabase and install Velociraptor as a backdoor. No ransomware was deployed in the case it describes; the staging matched earlier Warlock intrusions step for step.
The research travelled. Within weeks it was being retold, in Russian, on underground forums we collect from. Forum audiences read vendor research closely: the write-up that helps defenders patch also tells other crews which servers are worth scanning for.

Who is behind Warlock
Symantec calls the actor Longlegs and treats it as the group Microsoft tracks as Storm-2603. Microsoft assesses Storm-2603 as China-based with moderate confidence and has found no link to the separately tracked Linen Typhoon or Violet Typhoon. Unit 42 assesses with high confidence that its CL-CRI-1040 cluster is the same actor, while stating it cannot attribute the cluster to any nation-state. Sophos tracks the operator as GOLD SALEM and dates Warlock’s public debut to 10 June 2025, on the RAMP forum.
The lineage is older than the brand. Symantec has traced a stolen code-signing certificate used by Warlock operators back to the CamoFei and ChamelGang clusters, active since at least 2019. Unit 42 found an affiliate account called “wlteaml” in leaked LockBit 3.0 panel data, registered in April 2025 and sharing a Tox ID with AK47 ransom notes, and Check Point documented the group running LockBit Black alongside Warlock. The older “Warlock Dark Army” ransomware is unrelated.
The actor profile in our collection
FireIntel’s profile of the group records Warlock from 10 June 2025 — the day Sophos dates its RAMP debut and first leak site — and summarises the attribution picture: Storm-2603, a history with LockBit, and an overlap in victims with Black Basta, read as an “old affiliate” that went on to build its own encryptor. All four known sites, three leak-site addresses under the “Client Data Leak Show” name and a file portal, are reported offline.

A profile summary is an analysis, and we weigh it like any other source. Its Storm-2603 and LockBit links match Microsoft’s and Unit 42’s reporting; the Black Basta victim overlap is not established by the research cited here, so we carry it as a lead. The same discipline applies to the tooling the profile data associates with the group. The table separates what independent reporting corroborates from what it does not.
| Category | Tools in the profile | Also reported by |
|---|---|---|
| Credential theft | Mimikatz; Veeam-Get-Creds | Mimikatz: Microsoft, Sophos, Trend Micro |
| Defense evasion | Antiy, NSec and Rising drivers (BYOVD); a VMTools-based AV killer | Antiy driver: Check Point · NSec driver: Trend Micro |
| Discovery | Everything.exe; SecurityCheck | — |
| Exfiltration | Rclone | Trend Micro |
| Built-in tools | Minidump, msiexec, PowerShell Remoting, PsExec, RDP Patcher | msiexec: Symantec, ReliaQuest · PsExec: Microsoft, Trend Micro · Remoting, RDP Patcher: Trend Micro |
| Tunnels and storage | Azure Blob Storage, Catbox, Cloudflared, MinIO, OpenSSH, Supabase, VS Code tunnel, Yuze | VS Code tunnel: Symantec, Sophos, Trend Micro · Catbox: Symantec · Supabase: ReliaQuest · Cloudflared, Yuze: Trend Micro |
| Frameworks | Cobalt Strike, Velociraptor | Velociraptor: Sophos, Trend Micro, ReliaQuest · Cobalt Strike: Trend Micro |
| Remote management | Radmin, TightVNC | TightVNC: Trend Micro |
Uncorroborated entries — Veeam-Get-Creds, the Rising driver, the VMTools-based AV killer, Everything.exe, SecurityCheck, Azure Blob Storage, MinIO, OpenSSH and Radmin — are hunting leads, not evidence of use.
Four vulnerable drivers in fifteen months
- 2025 · Check Point
- A signed Antiy Labs driver behind the “Antivirus Terminator” tool
- 2025 · Sophos, Symantec
- A 2016 Baidu antivirus driver renamed googleApiUtil64.sys (CVE-2024-51324)
- Jan 2026 · Trend Micro
- NSecKrnl.sys, loaded by a fake TrendSecurity.exe to kill more than 30 security processes
- 2026 · Symantec
- K7RKScan (CVE-2025-1055); the driver used in the July case is unidentified
The rotation matters more than any single name on that list. Blocking one driver buys little; enforcing Microsoft’s vulnerable driver blocklist with memory integrity (HVCI) turned on, and alerting on any new kernel driver load on servers, closes the class.
Detection and response
Each technique below is tied to an artefact in the published telemetry for the July intrusion, not inferred from the group’s wider reputation. Where the report stops short — the exact CVE, the driver behind the AV/EDR killer — the mapping stops short too.
| Tactic | Technique | Evidence in this case |
|---|---|---|
| Initial access | T1190Exploit Public-Facing Application | On-premises SharePoint exploitation, assessed as the likely route; the exact 2026 CVE is not identified. |
| Persistence | T1505.003Web Shell | layout2sp.aspx written into the SharePoint LAYOUTS directory on 22 July. |
| Execution | T1059.001PowerShell | Encoded PowerShell writes the web shell and loads the ViewState deserialization gadget. |
| Discovery | T1087.002Domain Account | net user /domain and whoami on the second SharePoint server. |
| Discovery | T1482Domain Trust Discovery | nltest /domain_trusts alongside the first side-loading pair. |
| Defense evasion | T1574Hijack Execution Flow (DLL side-loading) | doexe.exe with doexeloc.dll; ssvagent.exe and logger.exe with their DLLs. |
| Defense evasion | T1070.004File Deletion | Numerically named staging files and doexeloc.dll removed on 24 July. |
| Command and control | T1105Ingress Tool Transfer | msiexec pulls three MSI packages from catbox.moe and Wasabi storage. |
| Persistence | T1098Account Manipulation | SPSEPRDSetup repeatedly added to local Administrators on three hosts. |
| Defense evasion | T1036Masquerading | The account name imitates SharePoint’s SPS-prefixed service accounts. |
| Command and control | T1572Protocol Tunneling | code-insiders.exe tunnel service install, from C:\Windows\debug. |
| Credential access | T1110.003Password Spraying | NetExec credential spraying against Active Directory. |
| Lateral movement | T1021.002SMB / Windows Admin Shares | net use to an internal IP, then copy of the \av tool set to each host. |
| Defense evasion | T1562.001Disable or Modify Tools | a.exe AV/EDR killer on at least 40 hosts, likely through a vulnerable driver. |
| Lateral movement | T1570Lateral Tool Transfer | Payload staged in SYSVOL\scripts\run and delivered by DFS Replication. |
| Impact | T1486Data Encrypted for Impact | run.exe and rune.exe on at least 33 hosts, with the ransom note. |
For on-premises SharePoint, Microsoft’s guidance is current patches, AMSI integration in Full Mode, Defender or an equivalent on every SharePoint server, then a machine-key rotation and an IIS restart. CISA’s July 2026 alert adds the order that matters: if compromise is suspected, find and remove web shells and machine-key harvesters before rotating keys, or the attacker simply reads the new ones. For SmarterMail, ReliaQuest’s advice is build 9511 or later and strict isolation of mail servers. Patching closes the door; it does not evict anyone already inside.
Windows telemetry worth alerting on
- New .aspx in LAYOUTS
- File creation under …\web server extensions\…\TEMPLATE\LAYOUTS (Sysmon 11 or EDR file events)
- IIS spawning tools
- w3wp.exe starting cmd.exe, powershell.exe, msiexec.exe or nltest.exe
- Mail service spawning a shell
- MailService.exe starting cmd.exe or msiexec.exe on a SmarterMail server
- Local admin changes
- Security event 4732 on servers, especially SP-prefixed accounts outside change windows
- New services
- System event 7045 — a code or code-insiders tunnel service is never routine on a server
- Kernel drivers
- Sysmon 6 or EDR driver loads on servers; any new driver deserves a look
- SYSVOL
- New executables under SYSVOL\…\scripts, and processes whose parent is dfsrs.exe
For Microsoft Defender XDR, the advanced-hunting queries below turn those signals into searches. Each was checked with Microsoft’s Kusto language parser against the Defender table schema; none has been run against live telemetry for this post, so they are deliberately broad — expect to tune out your own administration tooling before alerting on them.
DeviceFileEvents
| where Timestamp > ago(30d)
| where FolderPath has @"\web server extensions\" and FolderPath has @"\template\layouts\"
| where FileName endswith ".aspx"
| project Timestamp, DeviceName, FolderPath, FileName,
InitiatingProcessFileName, InitiatingProcessCommandLineDeviceProcessEvents
| where Timestamp > ago(30d)
| where InitiatingProcessFileName in~ ("w3wp.exe", "MailService.exe")
| where FileName in~ ("cmd.exe", "powershell.exe", "pwsh.exe", "msiexec.exe", "nltest.exe")
| project Timestamp, DeviceName, InitiatingProcessFileName, FileName,
ProcessCommandLine, InitiatingProcessCommandLineDeviceProcessEvents
| where Timestamp > ago(30d)
| where (FileName in~ ("code.exe", "code-insiders.exe")
and ProcessCommandLine has_all ("tunnel", "service", "install"))
or (FileName =~ "msiexec.exe"
and ProcessCommandLine has_any ("catbox.moe", "wasabisys.com", "supabase.co"))
or (InitiatingProcessFileName =~ "dfsrs.exe" and FileName endswith ".exe")
| project Timestamp, DeviceName, AccountName, FileName, ProcessCommandLine,
InitiatingProcessFileName- Take SharePoint and mail servers off the open internet where you can. If they must stay reachable, put them behind an authenticated layer-7 proxy and block external access to SharePoint Central Administration.
- Hunt before you rotate: web shells, machine-key harvesters and unexpected ASPX files first, then new machine keys and an IIS restart on every server in the farm.
- Review local Administrators membership on SharePoint and adjacent servers against a known-good baseline, and alert on changes.
- Treat the 31 July pattern — one share copied to dozens of hosts in minutes — as a tripwire. Mass execution of the same binary from C:\Users\Public is rarely legitimate.
Indicators
Machine-readable indicators
- CSV 32 indicators with type, classification, context and source
- STIX 2.1 bundle Indicators, the Warlock malware family and the Storm-2603 intrusion set, with relationships; TLP:CLEAR
The primary report’s IOC appendix lists 19 SHA-256 hashes: five Warlock payloads, six malicious DLLs, six suspicious files, one AV/EDR killer and one vulnerable driver. They are reproduced below under the source’s own classifications. This is a report-wide set rather than a list of files from the 22–31 July case, and the report does not map every hash to a filename. A match warrants investigation; a non-match clears nothing, because this group changes tooling.
Warlock payload
5 hashes116ca4e88a1bcebb6c0da7fb431c8eca7b8ef3f9767194820c56091972ccac2c155fb1cbdaea12c83ba92d18c88cf38bbc42bb684f913ca0bc26fcf115426a556d07f1232dc59b84038fd0b2e75fdd3d5b825882bb0dba9e6724b7b0823fa3ad8b58f7811a2a2f2a5024220490473774f02759dd2dd904b5b9fabfbaae37125f8ce8d8270ee9de02644530b8dd7fa78973b4a3b80f121e2c5f45ae68cce196f9
Malicious DLL
6 hashes1edb2c0b537cd95bbd5fc16321b4c38a6adf325ccc7b588ad6acc980b0463b60206f27ae820783b7755bca89f83a0fe096dbb510018dd65b63fc80bd20c0326127b7591cf9e1283010ca98fa5dbe970a73fee0d8cde277639924c144718db7c0c46825fcc0d1bf7a8b192facb176d6bf916c9dccfd6fa994be691e3b0e585f4ee14240bac8277b0f6dd4d29ab5da20d246bcccae647e5fe8d19cdae7fe471b20fb3846c9ac53d1b841ada3a6b1091153fea41a169cb44fe0084097d1f4d45984
Suspicious file
6 hashes37f94fe1b4a106f02b6f74a69cbc05e69c17406f688beef4c9a045ffcbd2e65e9ceb01f8bf7d6dba2ae07f5bd6070de3ec67b5eb01f969b0ba85e74564fb83a7aaff04d84ef85353966aa4af186ff1254b72c068f33f802417b29dc23fb9f192e3204b05e2f3a29bb6e6fcc21dda77d7cd31dfa755c21da0aa8661b5619ee0a1eea631b5f7125239db0811e4682c2316ead69f9822e02d94fb5d8bf0d2faebedf7269f80f81e99d06a590d7ab374e12fdf7e5f55a02c2a46c342d670f8519fdf
AV/EDR killer
1 hash73c5268256c9da5488cd9e2b79013060ac321c7e54129344dc7b51e268af36ea
Vulnerable driver
1 hashae9f7fce57c7b928e659dccf0e00fa79cd9cd61a106f18d4e03f92dc3a03c295
SharePoint intrusion: network indicators and delivery paths (Symantec)
- Appendix host
- litter[.]catbox[.]moe
- Appendix host
- xn8xyt-drop[.]s3[.]wasabisys[.]com
- MSI 1, 28 Jul
- hxxps://litter[.]catbox[.]moe/6f5tdt.msi
- MSI 2, 28 Jul
- hxxps://s3[.]wasabisys[.]com/fortifs/vamd64.msi
- MSI 3, 28 Jul
- hxxps://xn8xyt-drop[.]s3[.]wasabisys[.]com/xn8xyt.msi
SmarterMail activity: infrastructure (ReliaQuest, February 2026)
- Domain
- auth[.]qgtxtebl[.]workers[.]dev
- Domain
- vdfccjpnedujhrzscjtq[.]supabase[.]co
- Domain
- 2-api[.]mooo[.]com
- IP addresses
- 162.252.198[.]197 · 199.217.99[.]93 · 157.245.156[.]118 · 45.127.35[.]186 · 178.128.103[.]218
Method, confidence and limits
The July chronology, host counts and IOC appendix come from Symantec and Carbon Black; the SmarterMail activity and its indicators from ReliaQuest; actor naming and history from Microsoft, Unit 42, Sophos, Check Point, Trend Micro and Symantec’s earlier research. Each is cited where it is used, and every indicator was checked against its source. Leak-site and forum figures come from FireIntel’s DDW Advance collection as queried on 3 October 2026; listings are dated by the leak site, counted as claims rather than confirmed victims, and the collection can have gaps.
Confidence follows common intelligence practice. High confidence means the judgment rests on direct observation in our collection or on several independent sources that agree. Moderate means the evidence is credible but incomplete, or comes from a single source. Low means the judgment is plausible but thinly supported. “No assessment” means we lack an independent basis to judge.
The diagrams are analyst reconstructions. Screenshots were captured from the FireIntel console on 3 October 2026 and redacted before publication: victim names are covered with fixed-width bars and onion addresses are withheld. Beyond choosing which listings to show and highlighting the Warlock row of the forum tracker, nothing in them was altered. No unnamed victim in the Symantec report is identified here.
Sources
- Symantec & Carbon Black — Warlock Ransomware Attackers Hit Water and Telecom Operators (1 October 2026)
- BleepingComputer — Warlock ransomware breach SharePoint in water, telecom operator attacks (2 October 2026)
- CISA — CISA Urges SharePoint Hardening After New Exploitations (14 July 2026)
- ReliaQuest — Storm-2603 Exploits CVE-2026-23760 to Stage Warlock Ransomware (9 February 2026)
- The Hacker News — Warlock Ransomware Breaches SmarterTools Through Unpatched SmarterMail Server (10 February 2026)
- Trend Micro — Dissecting a Warlock Attack (16 March 2026)
- Symantec — Warlock Ransomware: Old Actor, New Tricks? (22 October 2025)
- Sophos — GOLD SALEM’s Warlock operation joins busy ransomware landscape (September 2025)
- Unit 42 — Project AK47: Uncovering a Link to the SharePoint Vulnerability Attacks (5 August 2025)
- Check Point Research — Before ToolShell: Exploring Storm-2603’s Previous Ransomware Operations (2025)
- Microsoft Threat Intelligence — Disrupting active exploitation of on-premises SharePoint vulnerabilities (22 July 2025)