Coverage from Dark Reading indicates that a Chinese ransomware outfit, known as Warlock, is exploiting Microsoft technologies to target large and critical organizations in Spanish- and Portuguese-speaking regions.
The Warlock group, also tracked as Longlegs and Storm-2603, has shifted its focus to organizations in countries where Spanish or Portuguese are spoken. This recent activity targets fewer, more valuable entities, including a water utility, a telecommunications provider, a regional government body, and a university. Warlock gains initial access by exploiting Microsoft SharePoint vulnerabilities, previously using the ToolShell exploit chain and potentially newer ones. After gaining access, the group employs techniques like DLL sideloading, using signed drivers to disable security processes, and living-off-the-land tactics, such as leveraging Visual Studio Code's remote tunneling feature. A notable tactic is staging the ransomware payload in the domain's SYSVOL share, allowing Active Directory replication to spread it to domain controllers, a more efficient method than traditional remote execution tools. This targeted approach, combined with its exploitation of Microsoft technologies, distinguishes Warlock from typical ransomware operations and raises questions about its evolving motivations and operational strategy.
Source: Dark Reading
