Storm-2603 — Ransomware Profile

Storm-2603 is a ransomware operation that Microsoft assesses with moderate confidence to be China-based, an attribution Secureworks CTU researchers say they have insufficient evidence to corroborate. Tracked by Secureworks as GOLD SALEM, and assessed by Palo Alto Networks Unit 42 with moderate confidence to overlap with the cluster it designates CL-CRI-1040, the group has been compromising networks since March 2025 according to CTU, and drew wide attention in July 2025 when it exploited the SharePoint ToolShell vulnerability chain against on-premises servers. Microsoft reports it has deployed both Warlock and LockBit ransomware.

Also tracked as

GOLD SALEM, Warlock Group

IntelFusions coverage (1)

Vendor research

Read the full analysis on IntelFusions