Japan

warlock

The Warlock ransomware and operator(s) are believed to be attributed to Storm-2603, a China-based threat actor who is also known to have deployed LockBit ransomware. There's also a crossover between victims with Black Basta. Both are RaaS and have a long list of known and unknown affiliates. Having said that, this is possibly an affiliate (likely a cybergroup) of both of those groups. The Alliance & Association would technically be Encryptor Sharing, but this is…

First seen 2025-04-02 · Last seen 2025-11-06 · 5 Japan claims

CVEs named by the source: CVE-2026-23760, CVE-2025-40551, CVE-2025-49704, CVE-2025-49706, CVE-2025-14611

Cached from ransomware.live. 2026-10-01 PT. Leak sites are not linked.

tein.co.jp

JP

Discovered: 2025-11-06 <span class="ransom-ago">(10mo ago)</span>

tein.co.jp

accsnet.com

JP

Discovered: 2025-08-17 <span class="ransom-ago">(13mo ago)</span>

all data

accsnet.com

hitachi-hta.com

JP

Discovered: 2025-08-17 <span class="ransom-ago">(13mo ago)</span>

all data

hitachi-hta.com

KMMP

JP

Discovered: 2025-06-11 <span class="ransom-ago">(15mo ago)</span>

kmmp.com.pe

ssi-mi

JP

Discovered: 2025-06-11 <span class="ransom-ago">(15mo ago)</span>

ssi-mi.com