Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Media Buying Briefing: Attivo breathes new life into Hill Holliday and DNY with senior media hires

    Why brands are shifting toward ‘less precise, more accurate’ gauges for paid social

    WTF is Markdown for AI agents? 

    Facebook X (Twitter) Instagram
    • Artificial Intelligence
    • Business Technology
    • Cryptocurrency
    • Gadgets
    • Gaming
    • Health
    • Software and Apps
    • Technology
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Tech AI Verse
    • Home
    • Artificial Intelligence

      Read the extended transcript: President Donald Trump interviewed by ‘NBC Nightly News’ anchor Tom Llamas

      February 6, 2026

      Stocks and bitcoin sink as investors dump software company shares

      February 4, 2026

      AI, crypto and Trump super PACs stash millions to spend on the midterms

      February 2, 2026

      To avoid accusations of AI cheating, college students are turning to AI

      January 29, 2026

      ChatGPT can embrace authoritarian ideas after just one prompt, researchers say

      January 24, 2026
    • Business

      The HDD brand that brought you the 1.8-inch, 2.5-inch, and 3.5-inch hard drives is now back with a $19 pocket-sized personal cloud for your smartphones

      February 12, 2026

      New VoidLink malware framework targets Linux cloud servers

      January 14, 2026

      Nvidia Rubin’s rack-scale encryption signals a turning point for enterprise AI security

      January 13, 2026

      How KPMG is redefining the future of SAP consulting on a global scale

      January 10, 2026

      Top 10 cloud computing stories of 2025

      December 22, 2025
    • Crypto

      Binance Denies Sanctions Breach Claims After $1 Billion Iran-Linked USDT Transactions Reported

      February 16, 2026

      Ray Dalio Says the World Order Has Broken Down: What Does It Mean for Crypto?

      February 16, 2026

      Cardano Whales are Trying to Rescue ADA Price

      February 16, 2026

      MYX Finance Lost 70% In a Week: What Triggered the Sharp Sell-Off?

      February 16, 2026

      What Really Happened Between Binance and FTX? CZ Finally Tells His Side

      February 16, 2026
    • Technology

      Media Buying Briefing: Attivo breathes new life into Hill Holliday and DNY with senior media hires

      February 16, 2026

      Why brands are shifting toward ‘less precise, more accurate’ gauges for paid social

      February 16, 2026

      WTF is Markdown for AI agents? 

      February 16, 2026

      ‘Being very careful’: Weeks after unveiling ad plans, OpenAI works to control the message

      February 16, 2026

      Hideki Sato, known as the father of Sega hardware, has reportedly died

      February 16, 2026
    • Others
      • Gadgets
      • Gaming
      • Health
      • Software and Apps
    Check BMI
    Tech AI Verse
    You are at:Home»Technology»Warlock ransomware may be linked to Chinese state
    Technology

    Warlock ransomware may be linked to Chinese state

    TechAiVerseBy TechAiVerseOctober 10, 2025No Comments4 Mins Read2 Views
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Reddit
    Warlock ransomware may be linked to Chinese state
    Share
    Facebook Twitter LinkedIn Pinterest WhatsApp Email

    Warlock ransomware may be linked to Chinese state

    Shutter2U – stock.adobe.com

    The operators of Warlock ransomware who exploited a set of SharePoint Server vulns earlier in 2025 likely have some kind of link to the Chinese government, researchers claim

    By

    • Alex Scroxton,
      Security Editor

    Published: 09 Oct 2025 17:00

    An emergent strain of ransomware known as Warlock – which was linked to multiple attacks orchestrated via vulnerabilities in on-premise Microsoft SharePoint Server instances during the summer of 2025 – has been linked to Chinese nation-state threat actors with a high degree of certainty by researchers at Halcyon’s Ransomware Research Centre.

    The SharePoint attacks arose through a vulnerability chain dubbed ToolShell, and were quickly linked to two known Chinese advanced persistent threat (APT) groups – Linen Typhoon and Violet Typhoon – by Microsoft.

    At the same time, Microsoft observed an unclassified threat actor known as Storm-2603 exploiting the ToolShell vulnerabilities, and swiftly stood up a link to Warlock. By late August, Warlock’s operators had claimed a number of victims including telecoms firms Colt and Orange.

    Two months on, Halcyon’s team now says that Warlock likely has ties to the Chinese APTs named by Microsoft, an assessment it has based on the gang’s early access to ToolShell, and new malware samples and technical analysis, which it claims highlights professional-grade development more consistent with well-funded state groups than criminals.

    “Our new technical analysis included identifying that Warlock planned from the beginning to deploy multiple ransomware families to confuse attribution, evade detection and accelerate impact. Based on technical overlaps, Halcyon tracks Warlock as the same group as Storm-2603 – Microsoft – and Cl-CRI-1040 – Palo Alto Unit 42,” said the team.

    The Halcyon team also firmed up previously suggested links to LockBit, stating that Warlock enjoyed “the distinction” of having been the final LockBit affiliate registered prior to the May 2025 data leak and had leveraged LockBit 3.0 as an operational tool and a development foundation for its own ransomware locker.

    Cynthia Kaiser, senior vice-president at Halcyon’s Ransomware Research Center, said the attribution did not come out of the blue given the high-profile and widely reported nature of the Sharepoint breach.

    “That said, these findings are particularly significant because it raises the concern of more ransomware attacks resulting from nation-state activity moving forward,” Kaiser told Computer Weekly. “Historically, ransomware attacks and nation-state attacks [or] espionage have had separate motivations and tactics to achieve their goals – to know that ransomware may be a runoff impact of nation-state activity puts more strain on network defenders who may not be prepared.”

    In this instance, Kasier said, it was hard to pin down the precise nature of the supposed relationship – Warlock’s operators may be leveraging personal connections having worked with Chinese state cyber agents in the past, or the collaboration may be rather more directly official, possibly even directly contracted. “We would expect most of this activity had tacit, but not necessarily explicit, approval from Beijing,” she added.

    New frontier

    This is not necessarily the first time financially motivated Chinese cyber criminals have been allowed to operate without repercussions from the government – Kaiser cited the Hafnium attacks on Microsoft Exchange Server back in 2021 which also demonstrated a degree of overlap.

    Nevertheless, Kaiser said she expected this trend to grow, and the gathering expansion of Chinese cyber espionage into adjacent areas represents a new and dangerous frontier for defenders.

    “It’s important for network defenders to be cognisant of the potential for espionage campaigns to morph into ransomware attacks. Network defenders may not naturally think about ransomware when they are dealing with a nation-state attack,” said Kaiser. “What used to be binary focuses between ransomware and nation-state attacks must now be considered together. This is not just a China issue. We need to be prepared for his becoming more commonplace across the board – this is not a one-off instance.”

    Read more on Hackers and cybercrime prevention


    • US government shutdown stalls cyber intel sharing

      By: Alex Scroxton


    • SolarWinds warns over dangerous RCE flaw

      By: Alex Scroxton


    • US politicians ponder Wimwig cyber intel sharing law

      By: Alex Scroxton


    • Warlock claims more victims as cyber attacks hit Colt and Orange

      By: Alex Scroxton

    Share. Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Telegram Email
    Previous ArticleForget training, find your killer apps during AI inference
    Next Article Chat Control encryption plans delayed after EU states fail to agree
    TechAiVerse
    • Website

    Jonathan is a tech enthusiast and the mind behind Tech AI Verse. With a passion for artificial intelligence, consumer tech, and emerging innovations, he deliver clear, insightful content to keep readers informed. From cutting-edge gadgets to AI advancements and cryptocurrency trends, Jonathan breaks down complex topics to make technology accessible to all.

    Related Posts

    Media Buying Briefing: Attivo breathes new life into Hill Holliday and DNY with senior media hires

    February 16, 2026

    Why brands are shifting toward ‘less precise, more accurate’ gauges for paid social

    February 16, 2026

    WTF is Markdown for AI agents? 

    February 16, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Ping, You’ve Got Whale: AI detection system alerts ships of whales in their path

    April 22, 2025680 Views

    Lumo vs. Duck AI: Which AI is Better for Your Privacy?

    July 31, 2025260 Views

    6.7 Cummins Lifter Failure: What Years Are Affected (And Possible Fixes)

    April 14, 2025154 Views

    6 Best MagSafe Phone Grips (2025), Tested and Reviewed

    April 6, 2025112 Views
    Don't Miss
    Technology February 16, 2026

    Media Buying Briefing: Attivo breathes new life into Hill Holliday and DNY with senior media hires

    Media Buying Briefing: Attivo breathes new life into Hill Holliday and DNY with senior media…

    Why brands are shifting toward ‘less precise, more accurate’ gauges for paid social

    WTF is Markdown for AI agents? 

    ‘Being very careful’: Weeks after unveiling ad plans, OpenAI works to control the message

    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    About Us
    About Us

    Welcome to Tech AI Verse, your go-to destination for everything technology! We bring you the latest news, trends, and insights from the ever-evolving world of tech. Our coverage spans across global technology industry updates, artificial intelligence advancements, machine learning ethics, and automation innovations. Stay connected with us as we explore the limitless possibilities of technology!

    Facebook X (Twitter) Pinterest YouTube WhatsApp
    Our Picks

    Media Buying Briefing: Attivo breathes new life into Hill Holliday and DNY with senior media hires

    February 16, 20263 Views

    Why brands are shifting toward ‘less precise, more accurate’ gauges for paid social

    February 16, 20263 Views

    WTF is Markdown for AI agents? 

    February 16, 20263 Views
    Most Popular

    7 Best Kids Bikes (2025): Mountain, Balance, Pedal, Coaster

    March 13, 20250 Views

    VTOMAN FlashSpeed 1500: Plenty Of Power For All Your Gear

    March 13, 20250 Views

    This new Roomba finally solves the big problem I have with robot vacuums

    March 13, 20250 Views
    © 2026 TechAiVerse. Designed by Divya Tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms & Conditions

    Type above and press Enter to search. Press Esc to cancel.