Back Darkreading Warlock Ransomware Hits Large Spanish, Portuguese Orgs
Breaking cybersecurity news, news analysis, commentary, and other content from around the world, with an initial focus on the Middle East & Africa, the Asia Pacific, Europe, and Latin America.
A year-old Chinese threat actor looks like a cybercrime gang, acts like a state-associated APT, and attacks organizations in unexpected places.
A Chinese ransomware outfit is exploiting Microsoft technologies to extort large and critical organizations in the Spanish- and Portuguese-speaking world.
The Warlock ransomware group — tracked by Symantec as "Longlegs" and by Microsoft as "Storm-2603" — has never fit neatly into any box. It surfaced in the summer of 2025, in a campaign that mirrored state-level espionage activity in its tactics, techniques, and procedures (TTPs). Yet it acted like a cybercrime gang, deploying ransomware against organizations without any apparent discrimination.
Recently, Warlock has devised another curveball. According to research from Symantec this week, it's been entirely focused on countries for which Spanish or Portuguese are the lingua franca. Like its step-brethren in espionage, it's also targeting fewer, more valuable targets. In the last two months, researchers observed Warlock attacks against four victims: a water utility , a telecommunications provider, a regional government body, and a university.
Related: South Africa Seeks Help After Cyberattack Targets Air Traffic Control
Chinese Hackers Exploit Microsoft Tech
Warlock exploits Microsoft SharePoint vulnerabilities as a way to gain initial access to its targets. Its earliest attacks utilized the exploit chain known as " ToolShell ."
Symantec couldn't say whether Warlock is still feasting off ToolShell, or whether it might be taking advantage of newer SharePoint vulnerabilities. For example, the Cybersecurity and Infrastructure Security Agency (CISA) added a handful of them to its Known Exploited Vulnerabilities (KEV) catalog over the summer. Dick O'Brien, principal intelligence analyst for the Symantec Threat Hunter Team, tells Dark Reading that "the exploits for these more recent vulnerabilities behave quite similarly" to ToolShell.
After establishing initial access, Warlock turns to long-established techniques like dynamic link library (DLL) sideloading, a signed but vulnerable driver to help terminate security processes ( BYOVD ), and living-off-the-land (LotL) techniques, like using Visual Studio Code's (VS Code) remote tunneling feature to establish remote access that blends with legitimate network traffic.
Warlock's best trick, perhaps, is the way it spreads its locker.
"They stage the ransomware payload in the domain's system volume (SYSVOL) to let ordinary Active Directory (AD) replication carry it to every domain controller, rather than pushing it to every host with a remote execution tool," O'Brien explains. It's not the first time attackers have tried this, he says, "but it’s a bit more efficient of a living-off-the-land approach, and less well known than using tools like PsExec or Windows Management Instrumentation (WMI)."
Related: Ghost Service Accounts Enable M365 Data Theft in Chile
Warlock Resists Being Put in a Box
Warlock has always specialized in exploiting Microsoft SharePoint, to a degree that immediately distinguished it from other, lesser ransomware groups.
In July 2025, Microsoft discovered that China-nexus threat actors were exploiting a handful of zero-day vulnerabilities in the on-premises version of its SharePoint platform, in the aforementioned ToolShell chain. Two of those threat actors — APT27 (aka Emissary Panda, Bronze Union, Linen Typhoon) and APT31 (aka Zirconium, Violet Typhoon) — were established, capable advanced persistent threats (APTs). The third was an as-yet-unknown threat actor. Microsoft labeled it "Storm-2603," and it's now better known as Warlock.
But Warlock stuck out. Whereas nation-state espionage groups like APT27 and APT31 might tools, tactics, and even zero-day vulnerabilities, Storm-2603 appeared less like a third state-espionage group than a cybercriminal troop. Microsoft noted that its campaigns culminated in delivering the eponymous Warlock ransomware, along with Lockbit. Even so, the analysts were unable to say for certain what the group's motivations were.
Related: China's FamousSparrow APT Spies on US Politics in Latin America
Warlock's latest activity provides more questions than answers. For example, it's been attacking the kinds of significant, critical organizations that one typically sees in the sights of APTs. And it's not simple to categorize its campaigns as focused like an APT, or broad and opportunistic as one might expect of a lower-level threat.
Ransomware Groups Exploit New Regions
Earlier Warlock campaigns crossed the world's largest developed countries: Brazil, India, Japan, Russia, Taiwan, and the United States — essentially a random sampling. Now Warlock is going after organizations in Spanish- and Portuguese-speaking countries, but those countries span Africa, Europe, and Latin America.
It's anyone's guess why Warlock has made this particular shift. It could have brought in new team members with Spanish and Portuguese language skills relevant for ransom negotiations. Or perhaps it's capitalizing on a niche that other threat actors haven't yet oversaturated.
"There was a time when these kinds of attacks were confined to the US, because that’s where all the most lucrative targets were. Then it moved to Europe and has since gone global. The Play group was one of the first to seriously target Latin America, but now we're seeing multiple groups target the region," O'Brien notes.
Chinese threat actors in particular have been increasingly involved in Latin America and countries that its primary languages. "This is likely driven by the sheer number of active attackers," O'Brien says. "It's getting harder and harder to find soft targets in Western countries, so they're moving further afield."
Nate Nelson is a journalist and award-winning scriptwriter. In addition to Dark Reading he writes for Darknet Diaries, the most popular show in cybersecurity across all media.
He began his career as a freelancer, ghostwriting Forbes and CNBC op-eds for executives in tech and finance. Then he transitioned to journalism at Threatpost, where he covered cybersecurity news and trends. Throughout those years he co-created a cybersecurity podcast, Malicious Life, which in its day climbed into the Top 20 technology podcasts charts on Apple Podcasts and Spotify.
He holds degrees from New York University and Bard College. As a born and bred New Yorker, he enjoys a superiority complex, but is polite enough to keep it to himself.
Want more Dark Reading stories in your Google results?
The State of Cloud Security: The Latest Challenges
The State of Cloud Security: The Latest Challenges
How Organizations Are Managing Incident Response
How Organizations Are Managing Incident Response
How Enterprises Are Developing Secure Applications
How Enterprises Are Developing Secure Applications
Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy
Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy
Essential News & Insights from Black Hat USA 2025
Essential News & Insights from Black Hat USA 2025
Static Analysis, Smarter Triage, Agentic Depth: A Practical AppSec Stack for AI-Driven Development
Static Analysis, Smarter Triage, Agentic Depth: A Practical AppSec Stack for AI-Driven Development
Effective Alert Triage: Reducing Noise and Finding Real Threats
Effective Alert Triage: Reducing Noise and Finding Real Threats
Cybersecurity Outlook 2027
Cybersecurity Outlook 2027
Threat Exposure Analytics: Measuring and Communicating Security Risk
Threat Exposure Analytics: Measuring and Communicating Security Risk
Benchmark Scores Are a False Flag
Benchmark Scores Are a False Flag
Operation DoppelBrand: Weaponizing Fortune 500 Brands
CISA Warns of 'Ongoing' Brickstorm Backdoor Attacks
Deja Vu: Salesforce Customers Hacked Again, Via Gainsight
Jaguar Land Rover Shows Cyberattacks Mean (Bad) Business
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
