VYPR
breachPublished Oct 1, 2026· 2 sources

Warlock Ransomware Targets Spanish and Portuguese Organizations

A sophisticated Chinese threat actor, active for at least a year, is deploying Warlock ransomware against organizations in Spain and Portugal, exhibiting characteristics of both cybercrime and APT groups.

A shadowy Chinese threat actor, operating for at least the past year, has been identified as the perpetrator behind recent Warlock ransomware attacks targeting organizations in Spain and Portugal. This group presents a complex profile, blending the financial motivations typical of cybercrime gangs with the advanced tactics and strategic targeting often associated with state-sponsored Advanced Persistent Threats (APTs).

The Warlock ransomware, while not as widely known as some other variants, appears to be a potent tool in this actor's arsenal. Details regarding the specific ransomware's capabilities, such as its encryption methods, evasion techniques, or data exfiltration strategies, are still emerging. However, the consistent targeting of entities within these specific European nations suggests a deliberate and focused campaign rather than opportunistic attacks.

Initial investigations into the attack vectors employed by the group are ongoing. Security researchers are working to understand how these organizations are being compromised, with possibilities including phishing campaigns, exploitation of unpatched vulnerabilities in public-facing applications, or compromised third-party software. The dual nature of the threat actor's profile makes it challenging to predict their exact modus operandi, as they may adapt their methods based on the target's security posture.

The impact on the affected organizations is currently under assessment. Ransomware attacks can lead to significant operational disruptions, data loss, financial extortion, and reputational damage. Given the potential for this group to exhibit APT-like behaviors, there is also a concern that data exfiltration might be a primary objective, with ransomware deployed as a secondary measure or to cover their tracks.

This actor's activity highlights a concerning trend where the lines between traditional cybercrime and state-aligned operations are increasingly blurred. The ability to operate with a degree of anonymity while deploying sophisticated tools like Warlock ransomware allows them to pursue diverse objectives, from financial gain to espionage or disruption.

Further analysis is required to attribute this campaign to specific Chinese state interests or to a purely financially motivated cybercrime syndicate. However, the sustained activity and the targeting of specific geographic regions indicate a well-resourced and organized threat operation. The cybersecurity community is monitoring this situation closely, anticipating further technical details and potential attribution.

Organizations in Spain, Portugal, and potentially other regions should remain vigilant against sophisticated phishing attempts and ensure their systems are patched against known vulnerabilities. Implementing robust endpoint detection and response (EDR) solutions and maintaining regular, offline backups are critical steps in mitigating the impact of such ransomware attacks.

The Warlock ransomware campaign, attributed to a China-nexus threat actor tracked as Longlegs or Storm-2603, has expanded its targeting to include critical infrastructure sectors such as water and telecommunications operators, alongside government bodies and universities. Recent activity highlights the exploitation of multiple Microsoft SharePoint Server vulnerabilities, including CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771, to achieve lateral movement and deploy ransomware. The attackers are employing advanced techniques such as webshells, DLL sideloading, and a Bring Your Own Vulnerable Driver (BYOVD) approach using the K7RKScan driver (CVE-2025-1055) to bypass defenses and achieve domain-wide encryption via SYSVOL replication.

Synthesized by Vypr AI