A New Wave of Ransomware Attacks Targets Spanish and Portuguese Organizations
A highly sophisticated Chinese threat actor, known as Warlock, has launched a series of targeted ransomware attacks against large organizations in Spain and Portugal. The attacks, which began last month, have compromised several critical infrastructure providers, including a water utility, a telecommunications company, and a regional government body.
Warlock’s tactics are particularly noteworthy because they blur the lines between state-sponsored espionage and cybercrime. On one hand, its techniques mirror those used by advanced persistent threats (APTs), such as APT27 and APT31, which have been linked to China. These groups often exploit zero-day vulnerabilities in Microsoft technologies to gain initial access to their targets. However, unlike traditional APTs, Warlock’s primary objective is not espionage but rather financial gain through extortion.
Warlock gains entry into its targets’ systems by exploiting vulnerabilities in Microsoft SharePoint, a popular collaboration platform used by many organizations. According to Symantec researchers, the group uses a technique called dynamic link library (DLL) sideloading, where it loads malicious code onto vulnerable systems. This is done using a signed but vulnerable driver to terminate security processes and establish remote access.
One of the most significant aspects of Warlock’s modus operandi is its use of living-off-the-land (LotL) techniques to spread its ransomware payload. Rather than pushing the payload directly to every host, the group stages it in the domain’s system volume (SYSVOL) share, allowing Active Directory replication to carry it to every domain controller. This approach makes it difficult for security teams to detect and mitigate the attack.
Warlock’s tactics have raised concerns about the group’s ability to adapt and evolve its techniques. While researchers believe that the group may still be using older exploits, such as ToolShell, they also suspect that it may be taking advantage of newer SharePoint vulnerabilities recently added to the Known Exploited Vulnerabilities (KEV) catalog.
The attacks highlight the ongoing threat posed by sophisticated ransomware groups like Warlock, which can target organizations in unexpected ways. While the group’s motivations and affiliations remain unclear, its ability to adapt and evolve its tactics makes it a significant concern for security professionals worldwide.
In light of these findings, we recommend that all organizations using Microsoft SharePoint review their vulnerability management practices and ensure they are up-to-date with the latest security patches. Additionally, implementing robust threat detection and incident response measures can help mitigate the risk of ransomware attacks like Warlock. By staying vigilant and proactive, organizations can reduce their exposure to these types of threats and protect themselves against the financial and reputational damage caused by targeted ransomware attacks.
Source: Dark Reading — 2026-10-01