A Chinese Ransomware Group Targets Large Organizations in Spain and Portugal
In a brazen cyberattack campaign, the Warlock ransomware group has been extorting large and critical organizations in the Spanish- and Portuguese-speaking world. The group, which has been tracked by Symantec as “Longlegs” and Microsoft as “Storm-2603,” has been exploiting Microsoft technologies to gain access to its targets’ systems.
Warlock’s tactics have raised eyebrows among security experts, as they appear to blend the sophistication of state-associated advanced persistent threats (APTs) with the brazenness of cybercrime gangs. The group surfaced in 2025, using a campaign that mirrored state-level espionage activity in its tactics, techniques, and procedures (TTPs). However, unlike typical APT groups, Warlock has been deploying ransomware against organizations without any apparent discrimination.
In recent months, researchers have observed Warlock attacks against four high-profile targets: a water utility, a telecommunications provider, a regional government body, and a university. The group’s exploits have been centered around Microsoft SharePoint vulnerabilities, with its earliest attacks utilizing the ToolShell exploit chain. Symantec couldn’t confirm whether Warlock is still using ToolShell or has moved on to newer vulnerabilities.
The initial access phase of the attack is particularly noteworthy. After exploiting SharePoint vulnerabilities, Warlock turns to established techniques like dynamic link library (DLL) sideloading and living-off-the-land (LotL) tactics. For example, the group uses Visual Studio Code’s remote tunneling feature to establish remote access that blends with legitimate network traffic.
One of the most intriguing aspects of Warlock’s approach is its use of Active Directory (AD) replication to spread the ransomware payload. By staging the payload in the domain’s system volume (SYSVOL) share, the group allows ordinary AD replication to carry it to every domain controller, rather than pushing it to every host with a remote execution tool.
Warlock has been described as a “cybercrime gang that acts like an APT” by Dick O’Brien, principal intelligence analyst for the Symantec Threat Hunter Team. The group’s unique blend of sophistication and brazenness makes it difficult to categorize or predict its next move.
The Warlock ransomware campaign serves as a stark reminder of the ongoing threat posed by sophisticated cybercrime groups. Organizations in high-risk sectors should remain vigilant, implementing robust security measures to protect against exploitation of Microsoft SharePoint vulnerabilities. This includes regular patching and monitoring of system volumes, as well as implementation of advanced threat detection tools.
For individual users, it’s essential to stay informed about emerging threats like Warlock. By keeping software up-to-date, using strong passwords, and being cautious when interacting with emails or attachments, you can significantly reduce your risk of falling victim to such attacks. Remember: cybersecurity is everyone’s responsibility.
Source: Dark Reading — 2026-10-01