www.security.com Warlock Ransomware Targets Critical Infrastructure in Spanish and Portuguese Regions
Article Content
- •Warlock ransomware has targeted critical infrastructure in Spanish- and Portuguese-speaking countries.
- •The group exploits Microsoft SharePoint vulnerabilities, including the ToolShell exploit chain.
- •Recent attacks involved disabling security software and efficient ransomware deployment via Active Directory.
The Warlock ransomware group, linked to the Chinese threat actor Longlegs (Storm-2603), has recently targeted critical infrastructure operators, including a water utility and a telecommunications provider, in Spanish- and Portuguese-speaking countries. In the past two months, at least four organizations have been attacked, with the group exploiting Microsoft SharePoint vulnerabilities, particularly the 'ToolShell' exploit chain. Warlock uses a vulnerable signed driver to disable security software and has been observed using Visual Studio Code's tunneling feature for covert access. The group has been active since June 2025 and continues to exploit both older and newer SharePoint vulnerabilities, as identified by CISA. The attacks have raised concerns due to their focus on critical infrastructure and the efficiency of the ransomware's deployment method, which utilizes Active Directory replication to spread across networks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (8)
Following this threat?
Track Lockbit, APT27 and CVE-2025-1055 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What organizations have been targeted?
What vulnerabilities are being exploited?
How does Warlock deploy its ransomware?
Continue Reading
Exploitation of PaperCut Vulnerabilities Threatens Educational Institutions Attackers are exploiting two recently disclosed vulnerabilities in PaperCut, CVE-2026-81578 and CVE-2026-82078, to steal credentials and gain privileged access in educational institutions across the U.S. and Europe. The Arctic Wolf Adversary Research Team reported that threat actors are chaining an authentication…
PAYLOAD Ransomware Exploits Active Directory GPO for Disruption In April 2026, Kaspersky's Global Emergency Response Team (GERT) responded to a ransomware incident at a manufacturing organization in the Middle East. Attackers gained domain-admin-equivalent control via a compromised FortiGate SSL VPN account and created a malicious Group Policy Object (GPO) named PAYLOAD. This GPO…