Warlock
From extortion.wiki, the ransomware notes archive
2 archived notes associated with the upstream family directory warlock. The family label follows ThreatLabz; any link to negotiation records uses an explicit archive alias mapping.
Archived note files
2 supported · 0 skipped| Original filename | File type | Content hash | Source | Internal archive |
|---|---|---|---|---|
| How to decrypt my data.txt | Plain text (.txt) | a31462c79ca26ef8… | Upstream file | Read archived source |
| How_to_decrypt_my_data.txt | Plain text (.txt) | 26a529f018dab1f1… | Upstream file | Read archived source |
Dataset provenance and citation
| Upstream collector | Zscaler ThreatLabz |
|---|---|
| Source repository | ThreatLabz/ransomware_notes |
| Source directory | warlock |
| Snapshot commit | 2bbf5b4ecda84837c4a71af1a99c6821920f051a |
| Dataset snapshot | Jun 26, 2026, 10:27 PM |
| Synchronization time | Jul 22, 2026, 11:47 AM |
| Source status | Complete |
| License | MIT; preserved notice |
| Stable internal citation | extortion.wiki. Warlock ransomware notes. ThreatLabz/ransomware_notes snapshot 2bbf5b4ecda84837c4a71af1a99c6821920f051a. https://extortion.wiki/notes/warlock/. |