The China-linked Warlock ransomware operation, tracked as Storm-2603 by Microsoft and Longlegs by Symantec, has narrowed its targeting to high-value organizations in Spanish- and Portuguese-speaking countries. After gaining entry through on-premises Microsoft SharePoint flaws, the group uses living-off-the-land techniques and Active Directory replication to distribute its encryptor. Symantec reports four victims in the last two months: a water utility, a telecommunications provider, a regional government body, and a university.
How initial access works
Warlock specializes in SharePoint as an entry point to a degree that sets it apart from other extortion crews. Its first wave in the summer of 2025 relied on the exploit chain called ToolShell against the on-premises version of the platform.
Symantec researchers could not confirm whether current intrusions still use ToolShell or have moved to newer SharePoint flaws. Several additional SharePoint issues were added to the Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) catalog over the summer. According to Dick O'Brien, principal intelligence analyst for the Symantec Threat Hunter Team, exploits for those newer flaws operate in a very similar manner to ToolShell.
That overlap matters for context. In July 2025, Microsoft found China-nexus actors exploiting a set of SharePoint zero-days in that same chain. Two were established espionage groups — APT27, also known as Emissary Panda, Bronze Union, and Linen Typhoon, and APT31, also known as Zirconium and Violet Typhoon. The third cluster was unknown at the time, designated Storm-2603, now called Warlock.
Post-exploitation toolkit
Once inside, Warlock relies on established, low-noise methods rather than custom implants:
- dynamic link library (DLL) sideloading to execute payloads under trusted binaries
- Bring Your Own Vulnerable Driver (BYOVD) — a signed but flawed driver abused to shut down security processes
- living-off-the-land (LotL) remote access via the remote tunneling feature in Visual Studio Code (VS Code), which blends with normal administrative traffic
For distribution, the group stages its locker in the domain system volume share, SYSVOL, and lets routine Active Directory (AD) replication copy it to every domain controller. That avoids pushing the binary host-by-host with a remote execution utility. Tools such as PsExec or Windows Management Instrumentation (WMI) are better known for that job, but the SYSVOL method is more efficient and less closely watched, researchers noted.
Microsoft observed earlier Warlock campaigns ending with deployment of the Warlock ransomware itself, alongside Lockbit, though analysts could not definitively establish the crew's motive.
From espionage overlap to extortion
Warlock emerged in the summer of 2025 with tradecraft resembling state-level espionage in tactics, techniques, and procedures (TTPs), but with indiscriminate ransomware deployment more typical of cybercrime.
Its early victim set looked essentially random across major economies: Brazil, India, Japan, Russia, Taiwan, and the United States. The recent shift is different in two ways: fewer victims, and higher value — critical infrastructure, telecom, government, and education — the profile more often associated with advanced persistent threats (APTs).
The linguistic focus is also new. The current targets sit in Spanish- or Portuguese-speaking countries spanning Africa, Europe, and Latin America.
Why the language-region pivot
No confirmed explanation exists for the pivot. Possibilities discussed by researchers include recruitment of members able to negotiate in Spanish and Portuguese, or deliberate pursuit of a less saturated niche.
Ransomware was once concentrated in the US, where the most lucrative victims were located, then expanded across Europe and globally. The Play group was among the first to pursue Latin America in earnest, and multiple groups now do so. In O'Brien's assessment, the sheer volume of active crews makes soft targets harder to find in Western countries, pushing operators further afield. Chinese-linked actors in particular have become more active in Latin America and related language regions.
See CISA alert urging SharePoint hardening after new exploitations and Microsoft analysis of on-premises SharePoint exploitation.
Detection and mitigation
No incident-specific indicators, hashes, or patch versions were provided in the source material for this wave. Based only on the techniques described, defenders with on-premises SharePoint and AD should:
- prioritize hardening and patching of internet-exposed SharePoint, following CISA KEV guidance
- audit writes to
SYSVOLand review Group Policy replication anomalies - enforce Microsoft's vulnerable-driver blocklist and alert on BYOVD-style service installs
- monitor for unauthorized
VS Codetunnel activity and restrict remote tunneling where not needed - hunt for DLL sideloading and anomalous use of
PsExecandWMIalternatives
Technical background — general concepts only
The following explains this class of activity in general terms. These are illustrative examples, not evidence from this Warlock wave.
SharePoint server-side chains of this type typically combine authentication bypass with deserialization or tool-pane abuse to achieve remote code execution, after which the attacker runs only signed system tools. DLL sideloading abuses application search order: a legitimate executable loads a malicious library of the same name from its working directory. BYOVD abuses a legitimate signed kernel driver with a known flaw to kill protected processes from kernel mode.
Abuse of SYSVOL for propagation relies on the fact that domain controllers replicate its contents by design. A generic audit for unexpected executables staged there might look like:
# Illustrative generic hunt - not a Warlock IOC
Get-ChildItem -Recurse \\example.local\SYSVOL\ | Where-Object {$_.Extension -in '.exe','.dll','.ps1'} | Sort-Object LastWriteTime -Descending
Similarly, unauthorized VS Code tunnels can be hunted generically, since the tunnel binary often appears as code tunnel or code-tunnel:
# Illustrative generic hunt - not a Warlock IOC
ps aux | grep -i "code.*tunnel"
Get-WinEvent -LogName "Microsoft-Windows-Sysmon/Operational" | Where-Object { $_.Message -match "tunnel" }
Defensively, restrict who can write to SYSVOL, require code-signing policies, apply the Windows driver blocklist, and disable or allowlist remote development tunnels.