Threat Intelligence

Chinese ransomware group Warlock targets Spanish- and Portuguese-speaking countries

China map outline, flag colors red, yellow glowing. Futuristic circuit board digital technology backdrop. High-tech data streams, innovation, modern design, connectivity global network.

Coverage from Dark Reading indicates that a Chinese ransomware outfit, known as Warlock, is exploiting Microsoft technologies to target large and critical organizations in Spanish- and Portuguese-speaking regions.

The Warlock group, also tracked as Longlegs and Storm-2603, has shifted its focus to organizations in countries where Spanish or Portuguese are spoken. This recent activity targets fewer, more valuable entities, including a water utility, a telecommunications provider, a regional government body, and a university. Warlock gains initial access by exploiting Microsoft SharePoint vulnerabilities, previously using the ToolShell exploit chain and potentially newer ones. After gaining access, the group employs techniques like DLL sideloading, using signed drivers to disable security processes, and living-off-the-land tactics, such as leveraging Visual Studio Code's remote tunneling feature. A notable tactic is staging the ransomware payload in the domain's SYSVOL share, allowing Active Directory replication to spread it to domain controllers, a more efficient method than traditional remote execution tools. This targeted approach, combined with its exploitation of Microsoft technologies, distinguishes Warlock from typical ransomware operations and raises questions about its evolving motivations and operational strategy.

Source: Dark Reading

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds