The ransomware group WarLock has escalated its activities sharply, claiming over 60 victims in September 2025. Also known as Gold Salem or Storm-2603, the group has targeted major enterprises, telecoms, and government agencies worldwide. The WarLock ransomware attacks surge highlights how quickly a new group can rise in prominence.

Who Is WarLock?

First observed in March 2025, WarLock has built a reputation for bold attacks. Security researchers link the group to advanced tactics, including exploitation of Microsoft SharePoint vulnerabilities. Some experts believe the group has possible Chinese connections.

WarLock is also known for its custom ToolShell chains, use of web shells for persistence, and abuse of legitimate tools like Velociraptor. For credential theft, the group relies on Mimikatz, while PsExec and Impacket support lateral movement. By leveraging Group Policy Objects (GPOs), WarLock deploys ransomware payloads across networks with speed.

High-Profile Victims

In recent months, WarLock has attacked organizations across North America, Europe, and South America. Victims range from small businesses to multinational corporations.

Two major telecom companies, Orange in France and Colt in the UK, were among the most notable cases. During the Colt breach, WarLock claims it stole around one million documents and is now auctioning the data.

Why September Saw a Surge

Security firm Sophos reports that WarLock increased its activity dramatically in September. Its leak site listed over 60 organizations, making it one of the most active ransomware groups of the month. The combination of zero-day exploits and aggressive data theft makes the group especially dangerous.

Defense Measures

Organizations can reduce risk by:

  • Applying patches quickly, especially for SharePoint flaws.
  • Monitoring internet-facing services.
  • Enforcing multi-factor authentication (MFA).
  • Using endpoint detection and response (EDR) solutions.
  • Maintaining strong incident response and backup strategies.

Conclusion

The WarLock ransomware attacks surge proves that new groups can rapidly become global threats. With over 60 victims in a single month and bold strikes on telecoms and enterprises, WarLock has positioned itself as one of 2025’s most dangerous ransomware operations. Organizations must act quickly, patch vulnerabilities, and strengthen defenses to avoid becoming the next target.


0 responses to “WarLock Ransomware Attacks Surge in September”