Transcript
Monday morning, every system comes online showing the same thing. Every file carries the same new extension, x2anylog. Renamed files and a document on every desktop that wasn't there Friday. It's a ransomware note. It calmly explains what happened, how you can recover your files, and most importantly, what happens if you refuse to pay. There's no phone number, just a Proton mail address, a QDocs ID and anonymous cryptic chat handle. That's who you negotiate your company's future with. The group behind this calls themselves Warlock. Researchers track them as Goldsalem. They showed up in early as 2025, and in six months they've torn through 60 organizations across three continents. Agriculture, government, and nuclear energy. They chain together zero-day exploits, weaponized forensic tools, and disable security controls with signed Chinese drivers. They might be criminals, or they might be spies. They might be both. And the country they're probably operating out of doesn't want to talk about it. Ransomware. You know the shape of it by now. Somebody gets into a corporate network, locks every file, and leaves a note. Pails in crypto, or we publish your client data, your internal emails, and your trade secrets. It's extortion and industry scale, and it has been for years. The groups that run these operations mostly sit inside of Russia. Not secretly, but it's effectively an open arrangement. Russian law enforcement leaves them alone as long as they follow one rule. Don't hit anything Russian. Don't hit any former Soviet state countries. That's the deal. And for years everyone's played by it. September 2025. Goldsalem posts the name of a Russian engineering firm, a company that builds equipment for power generation to their leak site, in what feels like a dystopian game show with a countdown timer and all. That's not by mistake. You don't accidentally list a Russian target. The groups that operate under Moscow's protection hard code exclusions into their ransomware. The malware literally checks the system language and quits if it detects Russian. Goldsalem didn't do that. Which tells you whoever they are, they're operating somewhere Moscow can reach them. Sophos. One of the biggest cyber security firms in the world. Their counter-threat unit tracked Goldsalem across 11 different incidents over a space of six months. What they found was a group that's fast evolving, so let me walk you through how one of their attacks operate. Now stick with me for a minute because it gets technical, but that's exactly where it gets interesting. In at least four of those 11 incidents, Sophos could confirm the entry point. Every time a Microsoft SharePoint. On-premise servers that companies host themselves. Microsoft had already disclosed that the attackers were chaining together four zero-day SharePoint vulnerabilities. An exploit chain tool called Toolshell. When proof-of-concept hit GitHub, Goldsalem used it in at least one confirmed intrusion, and that's how they got in. SharePoint's worker processes quietly call Windows Installer, which silently pulls down a file from an attacker-controlled domain. The Q flag means quiet mode. Every part of this looks like normal software doing normal things. And remember that URL because we're coming back to it. Once they hit a foothold, they run this. Now this command creates a new admin account with password abcd1234. The same password across multiple victims over multiple months. And minutes later, they hunt for LSAS. The Windows process is responsible for storing login credentials, so they can dump hash passwords and move deeper into the network. Up until this point, it's a fairly standard ransomware playbook. But then Goldsalem does two things that set them apart that nobody expected. That file they downloaded, v2.msi, it's Velociraptor. A legitimate open-source forensic tool that incident response is used to investigate breaches. Goldsalem repurposes it and use Velociraptor to remote execution platform to deploy Visual Studio Code, Microsoft's own code editor in tunnel mode. That creates an encrypted channel straight back to the attackers using Microsoft's own infrastructure. By using VS Code in tunnel mode, they aren't just bypassing firewalls, they're essentially turning the victim server into a remote development workstation for the attackers. Second, they know you're running endpoint detection. So they bring a tool called vmtools.exe, designed to stop antivirus and EDR agents. And to do that without triggering alerts, they use a technique called bring-your-own-vulnerable-driver. They load a legitimate but vulnerable driver into the kernel, where the security software can't stop them because it's legitimate. Now those drivers, one of them is a digitally signed by Beijing Rising Network Security Technology. The Chinese cybersecurity company and another, kl.sys, appears alongside it. Sophos had seen those exact drivers before, but where? Not in a ransomware attack, in Crimson Palace, a Chinese state-sponsored espionage campaign Sophos tracked in 2024, where those drivers were deployed to disable EDR while attackers ran a keylogger. That detail feeds into a broader picture CTO researchers were building about exactly who is behind these attacks. Okay, so let's talk about the elephant in the room. Is GoldSalem a Chinese state-sponsored group, or are they just criminals who happen to be based out of China? Microsoft says with moderate confidence that they're a China-based group. Sophos says CTUSS is with low confidence that they're at least partially composed of Chinese individuals. But let's look at the evidence. One, the tools to bring-your-own-vulnerable-drivers from Beijing Rising and Baidu. The Cloudfire workers' infrastructure. These are the patterns associated with Chinese threat actors, both criminal and state-sponsored. Two, the targets. When you look at Warlock's victim lists, some of the organizations jump out at you. Telecom providers in Europe. Nuclear energy research companies. Aerospace firms. Government-linked entities in Southeast Asia. These aren't financially attractive targets. They're intelligence targets. The kind of organizations that Chinese espionage groups have historically prioritized. Three, the willingness to attack both Russia and Taiwan. Russian ransomware groups won't touch Russia. And most cybercriminals stay clear of Taiwan because it risks drawing attention from Beijing. But GoldSalem hits both. Four, SharePoint. Early exploitation overlaps with early Microsoft activity observed from Violet Typhoon and Linen Typhoon. Now, there's precedent for this kind of overlap. A group called Bronze Starlight were caught in 2022 using this ransomware, including LockBit, as a smokescreen for espionage. Deploy ransomware, steal what you actually want, and everyone assumes it was just another criminal operation. But GoldSalem follow traditional ransomware tactics. They run leak sites and they act upon the threat of publishing data. Okay, so here's where I think this story gets really interesting. For years now, we've been told that cybercrime and cyberespionage are two separate worlds. Different motivations and different actors. Cybercriminals want money and nation-states want secrets. But GoldSalem blurs those lines, and maybe intentionally. So let's look at their victim profile. 64% of their targets are in IT and industrial technology. That's 20 points higher than the average across all ransomware groups. Some of these organizations, nuclear research, aerospace, telecom, they're exactly what an intelligence agency would target. But they also hit translation companies, an automotive firm, agriculture companies. That looks opportunistic and random. So what's really going on here? Well, the possibilities. One, GoldSalem is a purely criminal group that happens to be Chinese, whose access methods leads them to certain types of targets. Two, they're a criminal group whose members have connections to Chinese-based intelligence and they occasionally steal data of espionage value on the side. Three, they're primarily an espionage operation that uses ransomware as a cover to encrypt everything, exfiltrate what matters, and victim assumes it was just about money. Before we close it out, I want to take a split second to focus on something that researchers never really get access to, and it's honestly kind of amazing. GoldSalem made a huge mistake. Their tool staging server here was configured as an open directory, meaning Sophos researchers could just browse it like an open folder on the internet. And inside, they found the group's entire toolkit. Velociraptor, a digital forensic framework we spoke about earlier, they use for remote collection and control. CloudFare for encrypted tunneling. OpenSSH for remote shell access. Radman server for remote desktop sessions. But three days after we published a report about GoldSalem's use of Velociraptor, the group abandoned that domain and switched to a new one, which leads us to believe that the group were watching the researchers as closely as the researchers were watching them. What we do know is that GoldSalem is getting more sophisticated. If your organization runs an on-premise SharePoint server, patch it. If you're relying on EDR alone, know that these attacks bring tools specifically designed to kill it. And if you think ransomware is just a criminal problem, GoldSalem is a reminder that the line between crime and espionage is thinner than we'd like to believe.