Skip to content

Security3 publishers2 min readPublished Updated

Warlock ransomware group narrows its targets to large Spanish- and Portuguese-speaking organizations

Warlock, the group Microsoft tracks as Storm-2603, hit four organizations in Spanish- or Portuguese-speaking countries in two months, Symantec says. It works like the Chinese state groups it first appeared beside and extorts like a ransomware crew.

The Watch · Security desk

Illustration accompanying Warlock ransomware group narrows its targets to large Spanish- and Portuguese-speaking organizations

What happened

  • Symantec's four observed victims were a water utility, a telecommunications provider, a regional government body and a university.
  • Warlock gets initial access by exploiting Microsoft SharePoint, and its earliest attacks used the exploit chain known as ToolShell.
  • After entry it sideloads DLLs, uses a signed but vulnerable driver to kill security processes, and opens remote access through Visual Studio Code tunnels.
  • Microsoft saw the group's campaigns end in Warlock and LockBit ransomware but could not say for certain what its motives were.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure Organizations in these countries running on-premises SharePoint without the summer's KEV fixes are within Warlock's reach, because Symantec cannot rule out the newer flaws.
  • constraint Alerts built around PsExec or WMI fan-out are not looking for a payload that Active Directory replication delivers; writes to SYSVOL are where the staging shows.
  • precedent At two victims a month in one language region, Warlock is running a sustained regional campaign, and organizations in those countries are its likeliest next targets.

Symantec could not say whether the current wave still runs on ToolShell or on one of the newer SharePoint flaws that CISA added to its Known Exploited Vulnerabilities catalog over the summer [6]. For a defender the difference is small [7]. Dick O'Brien, principal intelligence analyst for Symantec's Threat Hunter Team, said "the exploits for these more recent vulnerabilities behave quite similarly" to ToolShell [7].

The way the locker is delivered is the least familiar step [10]. "They stage the ransomware payload in the domain's system volume (SYSVOL) share to let ordinary Active Directory (AD) replication carry it to every domain controller, rather than pushing it to every host with a remote execution tool," O'Brien said [9]. He said attackers have used the trick before, "but it's a bit more efficient of a living-off-the-land approach, and less well known than using tools like PsExec or Windows Management Instrumentation (WMI)" [10].

Microsoft first saw the group in July 2025. It was the third actor exploiting the ToolShell zero-days in on-premises SharePoint, alongside APT27 and APT31 [11]. Those two are established state espionage groups. Storm-2603 was new [11]. In its early campaigns it borrowed state-level espionage techniques but deployed ransomware without apparent discrimination, according to Dark Reading [2]. Symantec now sees fewer, more valuable targets [3]. Its count works out to two victims a month [1]. Dark Reading calls Warlock a Chinese outfit [13]. It says the victims are the kinds of critical organizations usually targeted by state groups [14].

The record supports two things: espionage-grade tradecraft and state-style target selection [2][14]. Symantec's findings, as reported, do not name the victims or the countries, and do not say whether data left any network before encryption. In my view a responder should still scope a Warlock case as a full intrusion. The locker arrives only after the SharePoint foothold, the disabled security tools and the remote tunnel are already in place [8][9].

What to watch

  • Symantec or Microsoft naming the SharePoint CVEs behind the current intrusions, giving defenders a specific patch list beyond ToolShell.
  • A disclosure from any of the four victims showing how long the attackers were inside before encryption.
  • Evidence of data theft or leak-site postings tied to Warlock, either of which would bear on whether the group wants money, intelligence or both.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories