Back Scworld Chinese ransomware group Warlock targets Spanish- and Portuguese
Coverage from Dark Reading indicates that a Chinese ransomware outfit, known as Warlock, is exploiting Microsoft technologies to target large and critical organizations in Spanish- and Portuguese-speaking regions.
The Warlock group, also tracked as Longlegs and Storm-2603, has shifted its focus to organizations in countries where Spanish or Portuguese are spoken. This recent activity targets fewer, more valuable entities, including a water utility, a telecommunications provider, a regional government body, and a university. Warlock gains initial access by exploiting Microsoft SharePoint vulnerabilities, previously using the ToolShell exploit chain and potentially newer ones. After gaining access, the group employs techniques like DLL sideloading, using signed drivers to disable security processes, and living-off-the-land tactics, such as leveraging Visual Studio Code's remote tunneling feature. A notable tactic is staging the ransomware payload in the domain's SYSVOL , allowing Active Directory replication to spread it to domain controllers, a more efficient method than traditional remote execution tools. This targeted approach, combined with its exploitation of Microsoft technologies, distinguishes Warlock from typical ransomware operations and raises questions its evolving motivations and operational strategy.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
