Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Sophos: GoldSalem Ransomware: Inside the Warlock Playbook

Sophos
08/17/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


Monday morning, every system comes online showing the same thing. Every file carries the same new extension, x2anylog. Renamed files and a document on every desktop that wasn't there Friday. It's a ransomware note. It calmly explains what happened, how you can recover your files, and most importantly, what happens if you refuse to pay. There's no phone number, just a Proton mail address, a QDocs ID and anonymous cryptic chat handle. That's who you negotiate your company's future with. The group behind this calls themselves Warlock. Researchers track them as Goldsalem. They showed up in early as 2025, and in six months they've torn through 60 organizations across three continents. Agriculture, government, and nuclear energy. They chain together zero-day exploits, weaponized forensic tools, and disable security controls with signed Chinese drivers. They might be criminals, or they might be spies. They might be both. And the country they're probably operating out of doesn't want to talk about it. Ransomware. You know the shape of it by now. Somebody gets into a corporate network, locks every file, and leaves a note. Pails in crypto, or we publish your client data, your internal emails, and your trade secrets. It's extortion and industry scale, and it has been for years. The groups that run these operations mostly sit inside of Russia. Not secretly, but it's effectively an open arrangement. Russian law enforcement leaves them alone as long as they follow one rule. Don't hit anything Russian. Don't hit any former Soviet state countries. That's the deal. And for years everyone's played by it. September 2025. Goldsalem posts the name of a Russian engineering firm, a company that builds equipment for power generation to their leak site, in what feels like a dystopian game show with a countdown timer and all. That's not by mistake. You don't accidentally list a Russian target. The groups that operate under Moscow's protection hard code exclusions into their ransomware. The malware literally checks the system language and quits if it detects Russian. Goldsalem didn't do that. Which tells you whoever they are, they're operating somewhere Moscow can reach them. Sophos. One of the biggest cyber security firms in the world. Their counter-threat unit tracked Goldsalem across 11 different incidents over a space of six months. What they found was a group that's fast evolving, so let me walk you through how one of their attacks operate. Now stick with me for a minute because it gets technical, but that's exactly where it gets interesting. In at least four of those 11 incidents, Sophos could confirm the entry point. Every time a Microsoft SharePoint. On-premise servers that companies host themselves. Microsoft had already disclosed that the attackers were chaining together four zero-day SharePoint vulnerabilities. An exploit chain tool called Toolshell. When proof-of-concept hit GitHub, Goldsalem used it in at least one confirmed intrusion, and that's how they got in. SharePoint's worker processes quietly call Windows Installer, which silently pulls down a file from an attacker-controlled domain. The Q flag means quiet mode. Every part of this looks like normal software doing normal things. And remember that URL because we're coming back to it. Once they hit a foothold, they run this. Now this command creates a new admin account with password abcd1234. The same password across multiple victims over multiple months. And minutes later, they hunt for LSAS. The Windows process is responsible for storing login credentials, so they can dump hash passwords and move deeper into the network. Up until this point, it's a fairly standard ransomware playbook. But then Goldsalem does two things that set them apart that nobody expected. That file they downloaded, v2.msi, it's Velociraptor. A legitimate open-source forensic tool that incident response is used to investigate breaches. Goldsalem repurposes it and use Velociraptor to remote execution platform to deploy Visual Studio Code, Microsoft's own code editor in tunnel mode. That creates an encrypted channel straight back to the attackers using Microsoft's own infrastructure. By using VS Code in tunnel mode, they aren't just bypassing firewalls, they're essentially turning the victim server into a remote development workstation for the attackers. Second, they know you're running endpoint detection. So they bring a tool called vmtools.exe, designed to stop antivirus and EDR agents. And to do that without triggering alerts, they use a technique called bring-your-own-vulnerable-driver. They load a legitimate but vulnerable driver into the kernel, where the security software can't stop them because it's legitimate. Now those drivers, one of them is a digitally signed by Beijing Rising Network Security Technology. The Chinese cybersecurity company and another, kl.sys, appears alongside it. Sophos had seen those exact drivers before, but where? Not in a ransomware attack, in Crimson Palace, a Chinese state-sponsored espionage campaign Sophos tracked in 2024, where those drivers were deployed to disable EDR while attackers ran a keylogger. That detail feeds into a broader picture CTO researchers were building about exactly who is behind these attacks. Okay, so let's talk about the elephant in the room. Is GoldSalem a Chinese state-sponsored group, or are they just criminals who happen to be based out of China? Microsoft says with moderate confidence that they're a China-based group. Sophos says CTUSS is with low confidence that they're at least partially composed of Chinese individuals. But let's look at the evidence. One, the tools to bring-your-own-vulnerable-drivers from Beijing Rising and Baidu. The Cloudfire workers' infrastructure. These are the patterns associated with Chinese threat actors, both criminal and state-sponsored. Two, the targets. When you look at Warlock's victim lists, some of the organizations jump out at you. Telecom providers in Europe. Nuclear energy research companies. Aerospace firms. Government-linked entities in Southeast Asia. These aren't financially attractive targets. They're intelligence targets. The kind of organizations that Chinese espionage groups have historically prioritized. Three, the willingness to attack both Russia and Taiwan. Russian ransomware groups won't touch Russia. And most cybercriminals stay clear of Taiwan because it risks drawing attention from Beijing. But GoldSalem hits both. Four, SharePoint. Early exploitation overlaps with early Microsoft activity observed from Violet Typhoon and Linen Typhoon. Now, there's precedent for this kind of overlap. A group called Bronze Starlight were caught in 2022 using this ransomware, including LockBit, as a smokescreen for espionage. Deploy ransomware, steal what you actually want, and everyone assumes it was just another criminal operation. But GoldSalem follow traditional ransomware tactics. They run leak sites and they act upon the threat of publishing data. Okay, so here's where I think this story gets really interesting. For years now, we've been told that cybercrime and cyberespionage are two separate worlds. Different motivations and different actors. Cybercriminals want money and nation-states want secrets. But GoldSalem blurs those lines, and maybe intentionally. So let's look at their victim profile. 64% of their targets are in IT and industrial technology. That's 20 points higher than the average across all ransomware groups. Some of these organizations, nuclear research, aerospace, telecom, they're exactly what an intelligence agency would target. But they also hit translation companies, an automotive firm, agriculture companies. That looks opportunistic and random. So what's really going on here? Well, the possibilities. One, GoldSalem is a purely criminal group that happens to be Chinese, whose access methods leads them to certain types of targets. Two, they're a criminal group whose members have connections to Chinese-based intelligence and they occasionally steal data of espionage value on the side. Three, they're primarily an espionage operation that uses ransomware as a cover to encrypt everything, exfiltrate what matters, and victim assumes it was just about money. Before we close it out, I want to take a split second to focus on something that researchers never really get access to, and it's honestly kind of amazing. GoldSalem made a huge mistake. Their tool staging server here was configured as an open directory, meaning Sophos researchers could just browse it like an open folder on the internet. And inside, they found the group's entire toolkit. Velociraptor, a digital forensic framework we spoke about earlier, they use for remote collection and control. CloudFare for encrypted tunneling. OpenSSH for remote shell access. Radman server for remote desktop sessions. But three days after we published a report about GoldSalem's use of Velociraptor, the group abandoned that domain and switched to a new one, which leads us to believe that the group were watching the researchers as closely as the researchers were watching them. What we do know is that GoldSalem is getting more sophisticated. If your organization runs an on-premise SharePoint server, patch it. If you're relying on EDR alone, know that these attacks bring tools specifically designed to kill it. And if you think ransomware is just a criminal problem, GoldSalem is a reminder that the line between crime and espionage is thinner than we'd like to believe.

TL;DR

  • GoldSalem (Warlock) hit 60+ organizations in six months using chained SharePoint zero-days, targeting nuclear energy, aerospace, and government sectors across three continents.
  • The group repurposes legitimate tools — Velociraptor and VS Code tunnel mode — to establish covert command-and-control channels over Microsoft's own infrastructure, evading standard detection.
  • They disable EDR using a bring-your-own-vulnerable-driver technique with a signed Beijing Rising driver previously seen in a confirmed Chinese state espionage campaign, Crimson Palace.
  • GoldSalem blurs the line between cybercrime and espionage: their target profile, tooling, and willingness to hit Russian entities suggest possible state affiliation or intelligence tasking alongside ransomware operations.

Who Is GoldSalem and What Have They Done

GoldSalem, the threat actor behind the ransomware operation known as Warlock, emerged in early 2025 and within six months had compromised more than 60 organizations across three continents. Their target list is striking: nuclear energy research firms, aerospace companies, telecom providers in Europe, and government-linked entities in Southeast Asia — sectors that read less like financially motivated criminal targeting and more like an intelligence collection priority list. The group operates a leak site, issues ransom notes via Proton Mail and anonymous chat handles, and has demonstrated a willingness to hit both Russian and Taiwanese targets — a deliberate departure from the unwritten rules that govern most ransomware groups operating under Moscow's tacit protection.

Attack Chain: Zero-Days, Forensic Tools, and Signed Drivers

The Sophos Counter Threat Unit tracked GoldSalem across 11 incidents and confirmed that in at least four cases the initial access vector was on-premise Microsoft SharePoint servers, exploited via a chained zero-day toolkit called Toolshell. Once inside, the group creates a new admin account using the password 'abcd1234' — reused across multiple victims — then dumps LSASS credentials to move laterally. What distinguishes GoldSalem from standard ransomware operators is their use of Velociraptor, a legitimate open-source incident response tool, repurposed as a remote execution platform to deploy Visual Studio Code in tunnel mode. This creates an encrypted command-and-control channel over Microsoft's own infrastructure, effectively bypassing firewalls. To neutralize endpoint detection and response tools, they employ a bring-your-own-vulnerable-driver technique using a digitally signed driver from Beijing Rising Network Security Technology — the same driver Sophos previously observed in Crimson Palace, a confirmed Chinese state-sponsored espionage campaign from 2024.

Crime, Espionage, or Both?

The central analytical question this video poses is whether GoldSalem is a criminal group, a state-sponsored espionage operation, or a deliberate hybrid of both. Microsoft assesses with moderate confidence that the group is China-based; Sophos CTU assesses with low confidence that they are at least partially composed of Chinese individuals. The tooling — drivers from Beijing Rising and Baidu, Cloudflare Workers infrastructure — aligns with known Chinese threat actor patterns. Their target profile skews 20 percentage points higher toward IT and industrial technology than the ransomware average. A critical operational security failure exposed their full toolkit: their staging server was left as an open directory, allowing Sophos researchers to enumerate every tool in use. Three days after Sophos published findings on their Velociraptor usage, GoldSalem abandoned the domain — suggesting the group was actively monitoring the researchers investigating them.

Chapters

0:00 - Attack Scene: Ransomware Note
0:32 - Introducing GoldSalem / Warlock
1:06 - Ransomware Landscape Context
2:14 - Sophos CTU Investigation
3:35 - Velociraptor, VS Code & EDR Bypass
4:59 - Attribution: Crime or Espionage?
7:51 - Open Directory Mistake & Toolkit Exposed
8:36 - Takeaways and Recommendations

Key Quotes

0:54 "They might be criminals, or they might be spies. They might be both."
2:01 "The malware literally checks the system language and quits if it detects Russian. Goldsalem didn't do that."
3:57 "By using VS Code in tunnel mode, they aren't just bypassing firewalls, they're essentially turning the victim server into a remote development workstation for the attackers."
5:43 "These aren't financially attractive targets. They're intelligence targets. The kind of organizations that Chinese espionage groups have historically prioritized."
8:31 "Which leads us to believe that the group were watching the researchers as closely as the researchers were watching them."
8:50 "If you think ransomware is just a criminal problem, GoldSalem is a reminder that the line between crime and espionage is thinner than we'd like to believe."

FAQ

How did GoldSalem get into victim networks?

In at least four confirmed incidents, GoldSalem exploited on-premise Microsoft SharePoint servers by chaining four zero-day vulnerabilities using a tool called Toolshell. When proof-of-concept code appeared on GitHub, the group incorporated it into active intrusions almost immediately.

Why do researchers suspect a Chinese state connection rather than purely criminal motivation?

Several indicators point toward state affiliation: the use of drivers signed by Beijing Rising Network Security Technology (also seen in the Chinese espionage campaign Crimson Palace), Cloudflare Workers infrastructure associated with Chinese threat actors, a target list dominated by intelligence-priority sectors, and a willingness to attack Russian entities — something Moscow-protected criminal groups hard-code their malware to avoid.


Categories:
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Threat Intelligence
  • Security Operations
  • OT
  • IoT Security
  • Technical Deep Dive
  • Thought Leadership
  • Ransomware
  • Chinese Threat Actors
  • Zero-Day Exploitation
  • EDR Evasion
  • Bring-Your-Own-Vulnerable-Driver
  • Critical Infrastructure Security
  • Cyber Espionage
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Sophos: GoldSalem Ransomware: Inside the Warlock Playbook

              XStreaminars (watch here)

              • Aug
                27

                Becoming Agent Ready with Cyera: Essential Strategies and Insights

                08/27/202601:00 PM ET
                • Sep
                  03

                  Verge.io: Can You Afford Your Next Storage Refresh?

                  09/03/202601:00 PM ET
                  More events

                  Industry Events (Sponsor Hosted)

                  • Aug
                    27

                    Summer of Satori: FunFoneFarm's Transformation of Fraud into Seamless Integration

                    08/27/202601:00 PM ET
                    • Sep
                      23

                      Invisible Data: Understanding What Needs Protection

                      09/23/202601:00 PM ET
                      • Oct
                        08

                        Embrace AI Adoption While Maintaining Robust Security Measures

                        10/08/202612:00 PM ET
                        More events

                        Upcoming Webinar Calendar

                        • 08/27/2026
                          01:00 PM
                          08/27/2026
                          Becoming Agent Ready with Cyera: Essential Strategies and Insights
                          https://www.truthinit.com/index.php/channel/2081/becoming-agent-ready-with-cyera-essential-strategies-and-insights/
                        • 08/27/2026
                          01:00 PM
                          08/27/2026
                          Summer of Satori: FunFoneFarm's Transformation of Fraud into Seamless Integration
                          https://www.truthinit.com/index.php/channel/2086/summer-of-satori-funfonefarms-transformation-of-fraud-into-seamless-integration/
                        • 09/02/2026
                          12:00 PM
                          09/02/2026
                          Unified Data Security in Action: Uncover, Analyze, and Resolve Threats
                          https://www.truthinit.com/index.php/channel/2045/unified-data-security-in-action-uncover-analyze-and-resolve-threats/
                        • 09/03/2026
                          01:00 PM
                          09/03/2026
                          Verge.io: Can You Afford Your Next Storage Refresh?
                          https://www.truthinit.com/index.php/channel/2082/verge-io-can-you-afford-your-next-storage-refresh/
                        • 09/23/2026
                          01:00 PM
                          09/23/2026
                          Invisible Data: Understanding What Needs Protection
                          https://www.truthinit.com/index.php/channel/2087/invisible-data-understanding-what-needs-protection/
                        • 09/30/2026
                          04:00 AM
                          09/30/2026
                          AI Command Center: Optimizing Visibility and Control in Your Operations
                          https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/
                        • 10/08/2026
                          12:00 PM
                          10/08/2026
                          Embrace AI Adoption While Maintaining Robust Security Measures
                          https://www.truthinit.com/index.php/channel/2092/embrace-ai-adoption-while-maintaining-robust-security-measures/
                        • 11/19/2026
                          01:00 PM
                          11/19/2026
                          360View: Govern, Secure & Recover Your Microsoft 365 Environment
                          https://www.truthinit.com/index.php/channel/2076/360view-govern-secure-recover-your-microsoft-365-environment/
                        Truth in IT
                        • Sponsor
                        • About Us
                        • Terms of Service
                        • Privacy Policy
                        • Contact Us
                        • Preference Management
                        Desktop version
                        Standard version