Warlock Ransomware Targeted Spanish Speaking Nations

The ransomware group, also known as Storm-2603, compromised four organizations using SharePoint vulnerabilities.

Updated on Oct. 1, 2026 in Cybersecurity

Warlock Ransomware Targeted Spanish Speaking Nations

Live Poll

Do you trust local organizations to secure your personal data against international ransomware groups?

Between August and September 2026, the Warlock ransomware group launched attacks against entities in Spanish and Portuguese-speaking countries. The group, which first appeared in the summer of 2025, compromised a water utility, a telecommunications firm, a government body, and a university.

Why it matters

The campaign highlights an evolving threat landscape where hackers exploit common software vulnerabilities to gain network entry and facilitate ransomware deployment. By leveraging Active Directory replication, the group effectively spreads malicious payloads across entire victim infrastructures.

The Warlock group gains initial access through Microsoft SharePoint vulnerabilities before deploying ToolShell, DLL sideloading, and Visual Studio Code remote tunneling. Payloads are staged in domain system volume shares to propagate via Active Directory replication.

The players

Warlock

Also known as Longlegs or Storm-2603, this ransomware group is a Chinese-nexus threat actor.

Microsoft

This technology corporation provides security monitoring services and identified the group as a threat in 2025.

Symantec

A cybersecurity firm that tracks threat actors and identified the group under the moniker Longlegs.

The details

The attackers employ advanced tactics including Bring Your Own Vulnerable Driver (BYOVD) techniques to bypass security controls. Security researchers at Microsoft and Symantec track the entity as Storm-2603 and Longlegs, respectively.

Timeline

  1. The Warlock ransomware group first surfaced in the summer of 2025.

  2. Microsoft identified the group as a Chinese-nexus actor in July 2025.

  3. Four specific organizations were attacked between August 2026 and September 2026.

The Tech Race

This campaign represents a shift toward weaponizing standard enterprise administrative tools rather than relying solely on custom malware. By utilizing Microsoft's Active Directory replication protocols, the attackers circumvent traditional perimeter defenses and internal monitoring systems.

Organizations relying on SharePoint or Active Directory services must ensure their software is patched against known vulnerabilities to prevent unauthorized network access. Users may experience service disruptions or data outages if their local utility or government service becomes a target.

The takeaway

Maintaining rigorous update schedules for enterprise software remains a primary defense against coordinated ransomware campaigns. Proactive monitoring of system volume shares can help security teams detect and mitigate the spread of unauthorized payloads within a network.

Further reading

For more information on emerging digital threats, visit the Cybersecurity section.

Live Poll

Do you trust local organizations to secure your personal data against international ransomware groups?