Storm-2603 — Ransomware Profile
Storm-2603 is a ransomware operation that Microsoft assesses with moderate confidence to be China-based, an attribution Secureworks CTU researchers say they have insufficient evidence to corroborate. Tracked by Secureworks as GOLD SALEM, and assessed by Palo Alto Networks Unit 42 with moderate confidence to overlap with the cluster it designates CL-CRI-1040, the group has been compromising networks since March 2025 according to CTU, and drew wide attention in July 2025 when it exploited the SharePoint ToolShell vulnerability chain against on-premises servers. Microsoft reports it has deployed both Warlock and LockBit ransomware.Also tracked as
GOLD SALEM, Warlock Group
IntelFusions coverage (1)
- Phishing now starts most intrusions as attackers beat MFA 2026-07-29 · Cyber Incidents
Vendor research
- Disrupting active exploitation of on-premises SharePoint vulnerabilities Microsoft
- GOLD SALEM's Warlock operation joins busy ransomware landscape Secureworks CTU / Sophos