Ransomware · 5h ago

Warlock Targets Iberophone Orgs With Microsoft Tradecraft

Symantec says Warlock ransomware, tracked by Microsoft as Storm-2603 and by Symantec as Longlegs, has shifted to selective attacks on large organizations in Spanish- and Portuguese-speaking countries. In the last two months, the group hit four victims: a water utility, a telecom provider, a regional government body, and a university.

Warlock uses Microsoft SharePoint for initial access, then leans on techniques that look like normal administration: DLL sideloading, a signed vulnerable driver to kill security tools, and Visual Studio Code remote tunneling for remote control. It also stages its locker in SYSVOL so Active Directory replication spreads it across domain controllers, which makes the intrusion harder to separate from ordinary enterprise traffic and harder to cleanly contain.

For teams that rely on SharePoint and remote-admin tooling, the exposure is not just the ransomware payload but the access path and the camouflage around it. A targeted campaign like this can sit inside trusted Microsoft-flavored activity long enough to look routine until the extortion phase begins.

Timeline

Sources

1 source covering this story

Entities

Vendor digest: Microsoft

Part of the PlainSec briefing for 2026-10-01

Editions