warlock
The Warlock ransomware and operator(s) are believed to be attributed to Storm-2603, a China-based threat actor who is also known to have deployed LockBit ransomware. There's also a crossover between victims with Black Basta. Both are RaaS and have a long list of known and unknown affiliates. Having said that, this is possibly an affiliate (likely a cybergroup) of both of those groups. The Alliance & Association would technically be Encryptor Sharing, but this is…
CVEs named by the source: CVE-2026-23760, CVE-2025-40551, CVE-2025-49704, CVE-2025-49706, CVE-2025-14611
Cached from ransomware.live. 2026-09-19 PT. Leak sites are not linked.
