Skip to main content

Threats Tagged 'warlock'

View all threats tagged with 'warlock'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: warlock

Threats Tagged 'warlock'

Click on any threat for detailed analysis and mitigation recommendations

This analysis challenges the notion that cyber threat actors are always sophisticated and organized. Through examining three incidents, it reveals that attackers often make mistakes, face obstacles, and adapt their tactics based on trial and error. The incidents showcase how threat actors struggled with Windows Defender, mistyped commands, and failed to start malicious services. Despite using similar tactics and infrastructure across attacks, the perpetrators had to refine their methods in response to setbacks. The study emphasizes that understanding these roadblocks and attacker reactions provides valuable insights for improving cybersecurity defenses.

Join the discussion

GOLD SALEM is a financially motivated cybercrime group deploying Warlock ransomware through sophisticated tradecraft, including exploiting SharePoint vulnerabilities for initial access. Over six months and 11 incidents, they targeted IT, industrial, and technology sectors using ransomware variants such as Warlock, LockBit, and Babuk. Their operations involve advanced techniques like zero-day exploitation and repurposing legitimate tools (Velociraptor, VMTools AV killer, Cloudflared) to evade detection and maintain persistence. Executables are often named after victim organizations, indicating targeted attacks. While evidence suggests possible Chinese origins, the group primarily pursues financial gain. The threat poses a medium severity risk but demonstrates capabilities that could escalate impact if defenses are weak. European organizations in critical infrastructure and technology sectors should be vigilant against these tactics.

Join the discussion

Showing 1 to 2 of 2 results

Filters:Tag: warlock
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses