Skip to content
Unlisted Report logoUnlisted ReportSubscribe
Threat Intel

Warlock ransomware targets Spanish- and Portuguese-speaking orgs

The China-linked Warlock group, also tracked as Storm-2603, is exploiting SharePoint flaws to hit utilities, telecoms and governments.

By · Published · Updated · 6 min read

World map for the Warlock ransomware campaign

A China-linked ransomware group known as Warlock is focusing on large organizations in Spanish- and Portuguese-speaking countries, according to Symantec research reported by Dark Reading.

Who is Warlock?

Warlock is tracked by Symantec as Longlegs and by Microsoft as Storm-2603. It appeared in summer 2025, using tactics typical of state espionage while deploying ransomware like a criminal gang. That dual character is what makes the group so interesting to researchers: its operators move carefully, dwell in networks for extended periods and pick targets methodically — habits associated with intelligence collection — yet they finish the job by encrypting systems and demanding payment.

The multiple names reflect how different security companies mapped parts of the same activity before realizing they were looking at one actor. That kind of confusion is common with newer groups and often delays a coordinated defense.

The latest campaign

Over the past two months, Symantec saw attacks on four high-value victims:

  • A water utility
  • A telecommunications provider
  • A regional government body
  • A university

All four sit in Spanish- or Portuguese-speaking regions, and all are the kind of organization where disruption creates immediate public pressure — exactly the leverage a ransomware operator wants. A water utility or a regional government cannot simply stay offline for weeks while it rebuilds.

How it gets in

Warlock exploits Microsoft SharePoint vulnerabilities for initial access. Its early attacks used the "ToolShell" exploit chain, a set of flaws in on-premises SharePoint servers that allowed unauthenticated attackers to run code and steal the machine keys that sign authentication tokens. CISA added several newer SharePoint flaws to its Known Exploited Vulnerabilities catalog this summer, and Symantec could not rule out that Warlock is using them.

SharePoint is an attractive doorway because it is almost always reachable from the internet, deeply trusted inside the network, and full of documents worth stealing. Once inside, attackers can reuse stolen machine keys to mint valid sessions even after the original hole is patched — which is why patching alone is not enough.

Why it matters

Groups that blend espionage and ransomware are hard to classify and harder to defend against. Their choice of fewer, more valuable targets — including critical services such as water — suggests motives beyond money. Whether the encryption is the goal, a cover story for data theft, or a revenue stream running alongside espionage, the result for victims is the same: stolen data and paralyzed systems.

The geographic focus also matters. Organizations in Spain, Portugal and Latin America have historically received less attention from threat-intelligence vendors than US and Northern European targets, which can leave defenders without timely warnings tailored to their region.

What defenders should do

  • Patch on-premises SharePoint servers immediately and check CISA's KEV list for SharePoint entries.
  • Rotate SharePoint machine keys after patching, as stolen keys can let attackers return.
  • Limit SharePoint exposure to the internet where possible.
  • Hunt for signs of earlier compromise before assuming a clean bill of health — these operators dwell quietly before encrypting anything.
  • Make sure backups are offline or immutable, and test that you can actually restore from them.

Sources

Read next