Skip to content
Warlock Ransomware Targets Critical Infrastructure in Spanish and Portuguese Regions

Warlock Ransomware Targets Critical Infrastructure in Spanish and Portuguese Regions

First seen 1 Oct 2026, 17:04 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 1, 2026 at 17:05 UTC
  • •Warlock ransomware has targeted critical infrastructure in Spanish- and Portuguese-speaking countries.
  • •The group exploits Microsoft SharePoint vulnerabilities, including the ToolShell exploit chain.
  • •Recent attacks involved disabling security software and efficient ransomware deployment via Active Directory.

The Warlock ransomware group, linked to the Chinese threat actor Longlegs (Storm-2603), has recently targeted critical infrastructure operators, including a water utility and a telecommunications provider, in Spanish- and Portuguese-speaking countries. In the past two months, at least four organizations have been attacked, with the group exploiting Microsoft SharePoint vulnerabilities, particularly the 'ToolShell' exploit chain. Warlock uses a vulnerable signed driver to disable security software and has been observed using Visual Studio Code's tunneling feature for covert access. The group has been active since June 2025 and continues to exploit both older and newer SharePoint vulnerabilities, as identified by CISA. The attacks have raised concerns due to their focus on critical infrastructure and the efficiency of the ransomware's deployment method, which utilizes Active Directory replication to spread across networks.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2025-06-01
Warlock ransomware first identified
Warlock ransomware emerged, linked to the Longlegs threat actor exploiting SharePoint vulnerabilities.
Security
2025-06-10
CVE-2025-1055 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2025-07-08
CVE-2025-49704 and CVE-2025-49706 published
Two critical vulnerabilities in Microsoft SharePoint were published, later exploited by Warlock.
Security
2025-07-20
CVE-2025-53770 and CVE-2025-53771 published
Two additional vulnerabilities in Microsoft SharePoint were published, contributing to Warlock's attack methods.
Security
2026-10-01
Warlock attacks reported
Recent attacks targeted a water utility and a telecommunications provider, among others, in Spanish- and Portuguese-speaking countries.
Darkreading

More articles in this cluster (8)

Following this threat?

Track Lockbit, APT27 and CVE-2025-1055 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What organizations have been targeted?
Recent attacks have affected a water utility, a telecommunications provider, a regional government body, and a university.
What vulnerabilities are being exploited?
Warlock is exploiting multiple Microsoft SharePoint vulnerabilities, including CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771.
How does Warlock deploy its ransomware?
Warlock stages its ransomware payload in the domain's SYSVOL, allowing it to spread through Active Directory replication.