<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/warlock-ransomware-hits-large-spanish-portuguese-orgs-rfuxpj6oe" -->

---
title: Warlock Ransomware Hits Large Spanish, Portuguese Orgs
description: A Chinese threat group known as Warlock (tracked as Longlegs by Symantec and Storm-2603 by Microsoft) has shifted its ransomware targeting to large...
canonical: https://daily.dev/posts/warlock-ransomware-hits-large-spanish-portuguese-orgs-rfuxpj6oe
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Warlock Ransomware Hits Large Spanish, Portuguese Orgs | daily.dev
og:description: A Chinese threat group known as Warlock (tracked as Longlegs by Symantec and Storm-2603 by Microsoft) has shifted its ransomware targeting to large...
og:url: https://daily.dev/posts/warlock-ransomware-hits-large-spanish-portuguese-orgs-rfuxpj6oe
og:image: https://api.daily.dev/og/posts/RfuxpJ6OE.png
og:image:alt: Warlock Ransomware Hits Large Spanish, Portuguese Orgs
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Warlock Ransomware Hits Large Spanish, Portuguese Orgs

**[Dark Reading](https://daily.dev/sources/dr)** · 5 min read · 0 upvotes · 0 comments

## Summary

A Chinese threat group known as Warlock (tracked as Longlegs by Symantec and Storm-2603 by Microsoft) has shifted its ransomware targeting to large organizations in Spanish- and Portuguese-speaking countries, hitting a water utility, telecom provider, regional government body, and university in the last two months. The group exploits Microsoft SharePoint vulnerabilities, originally via the ToolShell exploit chain, and may now be leveraging newer SharePoint flaws added to CISA's KEV catalog. After gaining access, it uses DLL sideloading, BYOVD techniques, and VS Code remote tunneling, and spreads ransomware via SYSVOL replication across Active Directory domain controllers rather than pushing it host by host. Researchers remain uncertain whether Warlock is a cybercrime gang or state-associated actor, noting the shift may reflect new language capabilities or an effort to find less saturated targets as Western regions become harder to exploit.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.darkreading.com/cyberattacks-data-breaches/warlock-ransomware-spanish-portuguese>

## Questions this post answers

### What techniques does the Warlock ransomware group use to spread across a network after gaining initial access?

Warlock stages its ransomware payload in the domain's SYSVOL share so that ordinary Active Directory replication carries it to every domain controller, instead of pushing it to each host with a remote execution tool like PsExec or WMI. It also uses DLL sideloading, a vulnerable signed driver to terminate security processes (BYOVD), and VS Code's remote tunneling feature for living-off-the-land remote access.

_Security teams defending Active Directory environments can track emerging ransomware techniques like this on daily.dev._

### Which SharePoint vulnerabilities has the Warlock ransomware group exploited for initial access?

Warlock, also tracked as Storm-2603 or Longlegs, initially exploited the ToolShell exploit chain against on-premises Microsoft SharePoint, first identified alongside Chinese APT groups APT27 and APT31 in July 2025. CISA later added additional SharePoint vulnerabilities to its Known Exploited Vulnerabilities catalog, and researchers say exploitation of these newer flaws behaves similarly to ToolShell, though it's unconfirmed whether Warlock has adopted them.

_Developers patching on-premises SharePoint deployments can follow exploit trends like this on daily.dev._

### Which organizations has the Warlock ransomware group targeted recently in Spanish and Portuguese speaking countries?

Over a two-month span, Warlock attacked four victims: a water utility, a telecommunications provider, a regional government body, and a university, all located in Spanish- or Portuguese-speaking countries spanning Africa, Europe, and Latin America. This marks a shift from earlier campaigns that targeted Brazil, India, Japan, Russia, Taiwan, and the United States.

_Infrastructure defenders tracking ransomware group targeting shifts can follow updates like this on daily.dev._

## Similar posts on daily.dev

- [Warlock Ransomware Group Augments Post-Exploitation Activities](https://daily.dev/posts/warlock-ransomware-group-augments-post-exploitation-activities-jsn14sxmc) · Dark Reading · 0 upvotes · 0 comments
- [Web Shells, Tunnels, and Ransomware: Dissecting a Warlock Attack](https://daily.dev/posts/web-shells-tunnels-and-ransomware-dissecting-a-warlock-attack-pabj8acyc) · Trend Micro · 0 upvotes · 0 comments
- [Iranian hackers targeted major South Korean electronics maker](https://daily.dev/posts/iranian-hackers-targeted-major-south-korean-electronics-maker-73rq7fupn) · BleepingComputer · 0 upvotes · 0 comments
- [Ransomware groups switch to stealthy attacks and long-term access](https://daily.dev/posts/ransomware-groups-switch-to-stealthy-attacks-and-long-term-access-odq0idhho) · CSO Online · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#ransomware](https://daily.dev/tags/ransomware), [#active-directory](https://daily.dev/tags/active-directory), [#sharepoint](https://daily.dev/tags/sharepoint)

[View this post on daily.dev](https://daily.dev/posts/warlock-ransomware-hits-large-spanish-portuguese-orgs-rfuxpj6oe)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Warlock Ransomware Hits Large Spanish, Portuguese Orgs","url":"https://daily.dev/posts/warlock-ransomware-hits-large-spanish-portuguese-orgs-rfuxpj6oe","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/warlock-ransomware-hits-large-spanish-portuguese-orgs-rfuxpj6oe"},"datePublished":"2026-10-01T13:03:31.739Z","dateModified":"2026-10-01T13:03:58.764Z","description":"A Chinese threat group known as Warlock (tracked as Longlegs by Symantec and Storm-2603 by Microsoft) has shifted its ransomware targeting to large...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/a0caf605164dd39ecb9871df787736c4?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/a0caf605164dd39ecb9871df787736c4?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Dark Reading","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Dark Reading","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/dr","url":"https://daily.dev/sources/dr"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/warlock-ransomware-hits-large-spanish-portuguese-orgs-rfuxpj6oe","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,ransomware,active-directory,sharepoint","timeRequired":"PT5M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Dark Reading","item":"https://daily.dev/sources/dr"},{"@type":"ListItem","position":3,"name":"Warlock Ransomware Hits Large Spanish, Portuguese Orgs"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/warlock-ransomware-hits-large-spanish-portuguese-orgs-rfuxpj6oe#faq","mainEntity":[{"@type":"Question","name":"What techniques does the Warlock ransomware group use to spread across a network after gaining initial access?","acceptedAnswer":{"@type":"Answer","text":"Warlock stages its ransomware payload in the domain's SYSVOL share so that ordinary Active Directory replication carries it to every domain controller, instead of pushing it to each host with a remote execution tool like PsExec or WMI. It also uses DLL sideloading, a vulnerable signed driver to terminate security processes (BYOVD), and VS Code's remote tunneling feature for living-off-the-land remote access. Security teams defending Active Directory environments can track emerging ransomware techniques like this on daily.dev."}},{"@type":"Question","name":"Which SharePoint vulnerabilities has the Warlock ransomware group exploited for initial access?","acceptedAnswer":{"@type":"Answer","text":"Warlock, also tracked as Storm-2603 or Longlegs, initially exploited the ToolShell exploit chain against on-premises Microsoft SharePoint, first identified alongside Chinese APT groups APT27 and APT31 in July 2025. CISA later added additional SharePoint vulnerabilities to its Known Exploited Vulnerabilities catalog, and researchers say exploitation of these newer flaws behaves similarly to ToolShell, though it's unconfirmed whether Warlock has adopted them. Developers patching on-premises SharePoint deployments can follow exploit trends like this on daily.dev."}},{"@type":"Question","name":"Which organizations has the Warlock ransomware group targeted recently in Spanish and Portuguese speaking countries?","acceptedAnswer":{"@type":"Answer","text":"Over a two-month span, Warlock attacked four victims: a water utility, a telecommunications provider, a regional government body, and a university, all located in Spanish- or Portuguese-speaking countries spanning Africa, Europe, and Latin America. This marks a shift from earlier campaigns that targeted Brazil, India, Japan, Russia, Taiwan, and the United States. Infrastructure defenders tracking ransomware group targeting shifts can follow updates like this on daily.dev."}}]}
```

