Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.
Methodological note: This article is based on a single report from the Symantec Threat Hunter Team published on Dark Reading. No independently verifiable indicators of compromise (IoCs) or confirmations from other primary sources are available. Technical details and geographic attributions reflect Symantec's research exclusively.
The Warlock ransomware group, tracked as Longlegs by Symantec and Storm-2603 by Microsoft, has focused its attacks over the past two months on four large organizations in Spanish- and Portuguese-speaking countries. The campaign signals a technical escalation: instead of detectable remote execution tools, the group exploits legitimate Active Directory replication to propagate the payload, making lateral movement indistinguishable from ordinary domain traffic.
Warlock emerged in summer 2025 and is of Chinese origin, according to Symantec research. The four confirmed victims in recent months — a water utility, a telecommunications provider, a regional government agency, and a university — are located in regions spanning Africa, Europe, and Latin America. The source does not specify the exact countries nor attribute to O'Brien a direct connection with "three continents" or with "saturation of traditional English-speaking markets."
- Warlock struck four victims in Spanish- and Portuguese-speaking countries between August and September 2026, according to the Symantec Threat Hunter Team.
- The group exploits Microsoft SharePoint vulnerabilities for initial access, initially through the 'ToolShell' exploit chain discovered by Microsoft in July 2025.
- The ransomware payload is distributed via the SYSVOL share and Active Directory replication, without resorting to remote execution tools such as PsExec or WMI.
- Warlock employs living-off-the-land techniques including Visual Studio Code remote tunneling to hide command-and-control traffic.
Anatomy of the Attack: From SharePoint to SYSVOL
Initial access occurs through Microsoft SharePoint vulnerabilities. Microsoft identified Chinese threat actors exploiting zero-days in on-premises SharePoint in July 2025; Storm-2603 was the third actor involved, distinct from APT27 and APT31. Symantec reports that more recent exploitations exhibit similar behaviors, but does not confirm that Warlock is still using ToolShell specifically.
After the initial compromise, Warlock deploys DLL sideloading and bring-your-own-vulnerable-driver (BYOVD) — vulnerable but digitally signed drivers — to terminate endpoint protection processes. The source does not specify which processes are terminated nor the name of the driver employed.
"They stage the ransomware payload in the domain's system volume (SYSVOL) share to let ordinary Active Directory (AD) replication carry it to every domain controller, rather than pushing it to every host with a remote execution tool."
The mechanism described by O'Brien represents the operation's distinguishing trait. SYSVOL is the file share automatically replicated among all domain controllers in an Active Directory forest; it contains logon scripts, policies, and other group objects. Leveraging this infrastructure for payload distribution means the transfer occurs through ordinary domain replication channels, without generating anomalous network connections between arbitrary hosts.
VS Code Tunneling as a Covert Channel
For persistent remote access, Warlock abuses Visual Studio Code's remote tunneling feature, Microsoft's open-source development editor. The tunneling allows establishing TCP connections through Microsoft's cloud service, with traffic transiting over TLS to *.visualstudio.com or similar endpoints.
From a defensive perspective, this approach presents a classification problem: the traffic is authenticated, encrypted, and directed to known Microsoft infrastructure. The source does not specify which traditional detection techniques are evaded nor mention temporal or volume metrics as sole indicators of anomaly.
Geography as Strategy
The geographic concentration of recent months represents a shift from the 2025 campaigns, when Warlock hit Brazil, India, Japan, Russia, Taiwan, and the United States. The absence of specific names or countries for the four recent victims prevents plotting a precise map.
O'Brien stated: "It's getting harder and harder to find soft targets in Western countries, so they're moving further afield." He added: "There was a time when these kinds of attacks were confined to the US, because that's where all the most lucrative targets were. Then it moved to Europe and has since gone global." These quotes, reported by the source, describe a general trend without specifying that Warlock has deliberately abandoned "English-speaking markets" due to saturation.
The fact that victims are critical infrastructure organizations — utilities and telecommunications — suggests Warlock selects targets with high payment-pressure profiles. The source does not specify whether the group has recruited operators with Spanish or Portuguese language skills, nor whether the shift in focus received directives from a central command structure. It also remains unconfirmed whether victims paid the ransom or whether data was actually exfiltrated.
What to Do Now
Organizations with Microsoft infrastructure must specifically verify three vectors documented in the Symantec research.
First: check the SYSVOL share for staged ransomware payloads, since Warlock exploits this legitimate channel for distribution. Ordinary Active Directory replication generates no alerts by definition, making direct inspection of the share's contents necessary.
Second: examine Visual Studio Code installations and remote tunneling connections, given the group uses this legitimate tool for command and control. The source does not specify which patterns identify malicious tunneling.
Third: monitor the use of signed vulnerable drivers (BYOVD) for terminating security processes, a technique documented in the Symantec report. The source does not list specific drivers nor provide signatures for detection.
The Blurring Line Between Ransomware and APT
Warlock combines tactics traditionally associated with ransomware attacks — data encryption, payment pressure — with persistence and lateral movement methodologies typical of advanced persistent threat actors. The use of legitimate operating system tools and Microsoft applications for every phase of the attack, from distribution to communication, makes the categorical separation between the two operational models less clear-cut than conventional labels suggest. This interpretation reflects the author's analysis, not a finding from the source.
The source does not specify whether Warlock represents an isolated case or the start of a broader trend in Chinese cybercrime. The lack of public IoCs and reliance on a single report make it impossible to independently verify the threat's scope.
Information is based on the cited source and current as of publication.
Sources
- https://www.darkreading.com/cyberattacks-data-breaches/warlock-ransomware-spanish-portuguese
- https://www.darkreading.com/ics-ot-security/kansas-water-plant-pivots-analog-cyber-event
- https://www.darkreading.com/cyberattacks-data-breaches/south-africa-help-cyberattack-air-traffic-control
Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.