Activity timeline
Warlock appears in 2 tracked threats between and ; the busiest month was 2026-02 with 1 report.
ATT&CK techniques observed
- T1059 Command and Scripting Interpreter — Executionobserved in 2 of 2 tracked threats
- T1190 Exploit Public-Facing Application — Initial Accessobserved in 2 of 2 tracked threats
- T1505 Server Software Component — Executionobserved in 2 of 2 tracked threats
- T1003 OS Credential Dumping — Credential Accessobserved in 1 of 2 tracked threats
- T1005 Data from Local System — Collectionobserved in 1 of 2 tracked threats
- T1021 Remote Services — Lateral Movementobserved in 1 of 2 tracked threats
- T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 1 of 2 tracked threats
- T1036 Masquerading — Stealth (formerly Defense Evasion)observed in 1 of 2 tracked threats
- T1048 Exfiltration Over Alternative Protocol — Exfiltrationobserved in 1 of 2 tracked threats
- T1068 Exploitation for Privilege Escalation — Privilege Escalationobserved in 1 of 2 tracked threats
- T1070 Indicator Removal — Stealth (formerly Defense Evasion)observed in 1 of 2 tracked threats
- T1070.007 Clear Network Connection History and Configurations — Stealth (formerly Defense Evasion)observed in 1 of 2 tracked threats
- T1071 Application Layer Protocol — Command and Controlobserved in 1 of 2 tracked threats
- T1071.001 Web Protocols — Command and Controlobserved in 1 of 2 tracked threats
- T1078.003 Local Accounts — Privilege Escalationobserved in 1 of 2 tracked threats
Tracked threats
- Warlock (Water Manaul / Storm-2603) Ransomware Campaign with BYOVD, Web Shells, and Multi-Channel Tunneling via SharePoint ExploitationCRITICAL
- SmarterMail Dual-CVE Pre-Auth RCE Chain — CVE-2026-23760 Admin Password Reset + CVE-2026-24423 ConnectToHub RCE, CISA KEV, Mass Automated Exploitation, 2-Day Patch Weaponization via .NET DecompilerCRITICAL