Warlock, the group Microsoft tracks as Storm-2603, hit four organizations in Spanish- or Portuguese-speaking countries in two months, Symantec says. It works like the Chinese state groups it first appeared beside and extorts like a ransomware crew.
Perspective Coverage
6 publishers
- Builder
- Builder 32%
- Operator
- Operator 59%
- Investor
- Investor 9%
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+15
- Incentives30
- Confidence68
Cisco Talos links China-nexus UAT-11587 to 16 affected or targeted institutions in eight Asian countries, via a backdoor run through Microsoft 365. Its commands move through Outlook and OneDrive via Microsoft Graph, so defenders have no command server to block.
Perspective Coverage
3 publishers
- Builder
- Builder 32%
- Operator
- Operator 63%
- Investor
- Investor 5%
Reality
- Evidence62
- Adoption30
- Hype gap+8
- Incentives
- Insufficient
- Confidence65
Symantec says Warlock operators ran an AV/EDR killer across at least 40 machines in roughly two hours after a suspected SharePoint compromise. The ransomware payloads moved between domain controllers through SYSVOL replication.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+20
- Incentives
- Insufficient
- Confidence55
China-linked Warlock operators hit at least four organisations through SharePoint flaws in two months, Symantec says. Its report lists six 2026 SharePoint CVEs only as possible additions, and the entry it documents is still older flaws on servers never patched or mitigated.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+15
- Incentives
- Insufficient
- Confidence55
Ontinue says the Python implant takes tasking from SharePoint dead drops over Graph API, relays interactive sessions through Teams TURN, and moves all of it through the victim's own headless Edge.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+20
- Incentives40
- Confidence60
Prosecutors in Kansas say the group crossed state lines to reach ATMs it believed were architecturally softer, which makes the machine on the street the control that mattered. The FBI counts 700 such incidents in 2025.
Perspective Coverage
4 publishers
- Builder
- Builder 29%
- Operator
- Operator 54%
- Investor
- Investor 17%
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap+20
- Incentives50
- Confidence65
ESET says the group dropped McRat and Trochilus in 2025 and hit government targets in Belgium, Italy, Serbia and Poland. Its two new backdoors call home to Discord and the Microsoft Graph API.
Reality
- Evidence62
- Adoption58
- Hype gap+8
- Incentives60
- Confidence62
Broadcom's Threat Hunter Team says the same small team, the same infrastructure and one control panel serve both Chinese state espionage and a crypto-fraud sideline. Actor-type triage does not survive that.
Reality
- Evidence58
- Adoption68
- Hype gap+12
- Incentives62
- Confidence55