Warlock Ransomware Targeted Spanish and Portuguese Entities
The threat actor exploited Microsoft SharePoint to infiltrate critical infrastructure and public organizations.
Updated on Oct. 1, 2026 in Cybersecurity

Live Poll
Do you trust local organizations to secure your personal data against international ransomware groups?
Between August and September 2026, the Warlock ransomware group—also known as Storm-2603—executed attacks against four organizations across Spanish and Portuguese-speaking regions. These incidents represent the latest activity from a Chinese-nexus group that first emerged in the summer of 2025.
Why it matters
The group demonstrates a sophisticated ability to leverage core enterprise infrastructure for lateral movement and payload delivery. By targeting utilities and government entities, Warlock poses a significant operational threat to essential service providers.
The group maintains persistence by exploiting Microsoft SharePoint for initial access and utilizing ToolShell for post-compromise activity. It spreads ransomware by placing payloads in domain system volume shares, forcing replication via Active Directory.
The players
Warlock
A ransomware group, tracked by Symantec as Longlegs and Microsoft as Storm-2603, identified as a Chinese-nexus threat actor.
Microsoft
A global technology company that provides the SharePoint, Active Directory, and Visual Studio Code platforms targeted by the attackers.
Symantec
A division of Broadcom providing enterprise security software that tracks this specific group under the alias Longlegs.
The details
Warlock employs a complex multi-stage infection chain that includes DLL sideloading—a technique where a malicious dynamic link library is loaded by a legitimate application—and BYOVD, or Bring Your Own Vulnerable Driver, to bypass kernel security protections. The group also leverages Visual Studio Code remote tunneling to maintain covert access to infected networks. By placing payloads within Active Directory (the Microsoft service used to manage network permissions and user access) domain system volume shares, the group forces the ransomware to propagate automatically across the internal environment.
Timeline
Summer 2025: The Warlock ransomware group first appeared in the digital threat landscape.
July 2025: Microsoft formally identified the actor as Storm-2603.
August 2026 - September 2026: The group compromised four organizations including a water utility and a university.
The Tech Race
Warlock's emergence fits the trend of Chinese-nexus actors shifting focus toward targeted ransomware operations against regional government and utility providers. This campaign follows documented patterns of the group's global activity in markets like Brazil, India, and Japan.
Organizations relying on Microsoft SharePoint must ensure their instances are fully patched against known vulnerabilities to prevent initial infiltration. Security teams should monitor Active Directory system volume shares for unauthorized file activity to limit the spread of ransomware.
The takeaway
Warlock targets the fundamental trust relationships within enterprise networks by abusing tools like Active Directory and Visual Studio Code. Watch for further indicators of compromise associated with the group's specific use of DLL sideloading and remote tunneling.
Further reading
For more on evolving threat actor techniques, visit our coverage of Cybersecurity.
Live Poll
Do you trust local organizations to secure your personal data against international ransomware groups?






