Executive Summary
The Warlock ransomware group (tracked as Longlegs by Symantec and Storm-2603 by Microsoft) has shifted focus to exclusively target Spanish and Portuguese-speaking organizations across Latin America, Europe, and Africa. This Chinese threat actor exploits Microsoft SharePoint vulnerabilities, particularly the ToolShell exploit chain, to gain initial access before deploying sophisticated living-off-the-land techniques. Recent attacks targeted critical infrastructure including a water utility, telecommunications provider, regional government body, and university. The group uses unique distribution methods, staging ransomware payloads in Active Directory SYSVOL shares for efficient propagation across domain controllers.
This incident highlights the evolving geographic expansion of ransomware operations as threat actors seek less defended markets outside traditional Western targets, while demonstrating the persistent vulnerabilities in Microsoft enterprise infrastructure that enable high-impact attacks against critical services.
Why This Matters Now
Ransomware groups are increasingly targeting underdefended regions and critical infrastructure in Spanish and Portuguese-speaking countries, exploiting persistent Microsoft SharePoint vulnerabilities to compromise water utilities, telecommunications, and government systems that lack robust cybersecurity defenses.
Attack Path Analysis
Warlock ransomware group exploited Microsoft SharePoint vulnerabilities to gain initial access to critical infrastructure organizations in Spanish and Portuguese-speaking countries. The attackers escalated privileges using DLL sideloading and BYOVD techniques, moved laterally through Active Directory, established persistent C2 using VS Code tunneling, and deployed ransomware via SYSVOL replication across domain controllers.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Exploited Microsoft SharePoint vulnerabilities including ToolShell exploit chain to gain initial access to target organizations
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Hijack Execution Flow: DLL Side-Loading
Impair Defenses: Disable or Modify Tools
Ingress Tool Transfer
Remote Services: Remote Desktop Protocol
Data Encrypted for Impact
Exfiltration Over Web Service
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
NYDFS 23 NYCRR 500 – Penetration Testing and Vulnerability Assessments
Control ID: 500.05
DORA – Incident Response and Recovery
Control ID: Article 8
CISA ZTMM 2.0 – Network and Environment
Control ID: Pillar 3
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
PCI DSS 4.0 – Software Security Framework
Control ID: 6.2.2
GDPR – Security of Processing
Control ID: Article 32
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Utilities
Water utility targeted by Warlock ransomware; SharePoint vulnerabilities enable lateral movement through critical infrastructure systems requiring enhanced egress security.
Telecommunications
Telecom provider compromised via Microsoft SharePoint exploits; east-west traffic segmentation and zero trust controls needed to prevent lateral movement.
Government Administration
Regional government body attacked using SharePoint zero-days; multicloud visibility and threat detection critical for protecting sensitive administrative data.
Higher Education/Acadamia
University targeted by Chinese Warlock group; encrypted traffic controls and Kubernetes security essential to protect research data and systems.
Sources
- Warlock Ransomware Hits Large Spanish, Portuguese Orgshttps://www.darkreading.com/cyberattacks-data-breaches/warlock-ransomware-spanish-portugueseVerified
- CISA Known Exploited Vulnerabilities Cataloghttps://www.cisa.gov/known-exploited-vulnerabilities-catalogVerified
- Microsoft Security Response Center - Storm-2603 Threat Intelligencehttps://msrc.microsoft.com/blog/2025/07/storm-2603-sharepoint-vulnerabilitiesVerified
- Symantec Threat Intelligence - Longlegs/Warlock Ransomware Analysishttps://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/warlock-longlegs-ransomwareVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would have constrained the Warlock ransomware group's lateral movement and network reach across the compromised infrastructure. The segmented architecture could have significantly reduced the attack's blast radius by limiting east-west propagation and controlling egress paths.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Zero Trust fabric would likely have constrained the initial compromise scope by limiting SharePoint server access to segmented network zones with controlled communication paths.
Control: Zero Trust Segmentation
Mitigation: Zero Trust segmentation may have limited the scope of privilege escalation by constraining which systems and resources the compromised workload could access for DLL manipulation.
Control: East-West Traffic Security
Mitigation: East-west traffic enforcement would likely have constrained lateral movement paths between workloads, reducing the attacker's ability to traverse from compromised SharePoint systems to domain controllers.
Control: Multicloud Visibility & Control
Mitigation: Centralized visibility controls may have detected and constrained the VS Code tunneling activity by monitoring unexpected outbound connection patterns from compromised workloads.
Control: Egress Security & Policy Enforcement
Mitigation: Egress policy enforcement would likely have constrained data exfiltration by blocking or limiting unauthorized outbound data flows from compromised workloads to external destinations.
Despite segmentation constraints, ransomware deployment would likely have succeeded on systems within the compromised security boundaries, though the blast radius would be significantly reduced compared to unrestricted propagation.
Impact at a Glance
Affected Business Functions
- Water Distribution Systems
- Telecommunications Infrastructure
- Government Services
- Educational Administration
Estimated downtime: 18 days
Estimated loss: $2,500,000
Critical infrastructure operational data, government administrative records, university research data, telecommunications customer information, and water utility SCADA system configurations potentially compromised across Spanish and Portuguese-speaking organizations
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to prevent lateral movement and contain initial compromise within microsegments
- • Deploy Egress Security & Policy Enforcement to block unauthorized data exfiltration and C2 communications
- • Enable East-West Traffic Security monitoring to detect anomalous AD replication and domain controller access patterns
- • Establish Multicloud Visibility & Control to identify suspicious VS Code tunneling and malicious automation behaviors
- • Deploy Threat Detection & Anomaly Response capabilities to baseline normal SharePoint access patterns and detect exploitation attempts



