Keep your eyes on these

VERY IMPORTANT

Security Articles

RSS

Warlock operation joins busy ransomware landscape

released on 2025-09-17 @ 05:43:11 PM
GOLD SALEM, also known as Warlock Group, has emerged as a significant player in the ransomware landscape since March 2025. The group has compromised networks across North America, Europe, and South America, targeting a range of organizations from small entities to large corporations. GOLD SALEM operates a Tor-based dedicated leak site, publishing victim data and claiming to sell information to private buyers. The group's tactics include exploiting SharePoint vulnerabilities, using web shells for initial access, and employing tools like Mimikatz for credential theft. They have also been observed bypassing EDR systems and using legitimate tools for malicious purposes. The group's activities suggest a level of competence in their operations, with potential links to China-based actors, although this attribution remains unconfirmed.