Guide

China-Linked Warlock Ransomware Exploits SharePoint Flaws to Hit Water and Telecom Operators

A China-linked ransomware gang called Warlock has turned its attention to critical infrastructure in Spanish- and Portuguese-speaking countries, breaking i

A China-linked ransomware gang called Warlock has turned its attention to critical infrastructure in Spanish- and Portuguese-speaking countries, breaking in through Microsoft SharePoint. Symantec observed four victims in just the last two months: a water utility, a telecommunications provider, a regional government body and a university, Dark Reading reports.

The targets span Africa, Europe and Latin America. That's a geographic shift for a group that first surfaced in summer 2025, and it puts essential services squarely in the blast radius.

Spy-grade targets, criminal playbook

Warlock goes by several names. Symantec tracks it as Longlegs, and Microsoft calls it Storm-2603. It emerged alongside the Chinese state groups APT27 and APT31 during the ToolShell SharePoint zero-day wave, yet it behaves like a cybercrime outfit, deploying both Warlock and LockBit ransomware.

That blend is what makes it uncomfortable. The victims look like espionage targets, but the endgame is encryption and extortion. SC World describes the same focus on Spanish- and Portuguese-speaking organizations.

In through SharePoint, out through Active Directory

SharePoint remains the front door. The group historically used the ToolShell exploit chain and may now be using newer SharePoint flaws that behave similarly, according to SecurityWeek. Defenders already patching the separate SharePoint code-injection bug added to CISA's KEV list know how quickly these servers get webshelled.

Once inside, Warlock sideloads malicious DLLs and brings its own signed vulnerable driver to kill security software. It then uses Visual Studio Code's remote tunneling feature for command and control, a living-off-the-land trick that blends into normal developer traffic, as Cyber Security News details.

The cleverest move comes at the end. Instead of pushing ransomware with PsExec or WMI, the operators stage the payload in the domain's SYSVOL share. Active Directory replication then copies it to every domain controller for them, turning the network's own plumbing into a delivery system.

Ransomware takedowns have been piling up lately, from crews like KillSec, whose teenage leader was arrested. Warlock is a different animal: patient, well equipped and pointed at the systems that keep water running and phones connected.

Cyberpresso: daily cyber & AI brief

Free daily newsletter, read in 5 minutes.

Subscribe free