Cybersecurity
Ransomware
Threat Intelligence

Warlock Ransomware Shifts Tactical Focus Toward Ibero-American Networks

September 30, 2026
1 min read
Source
Warlock Ransomware Shifts Tactical Focus Toward Ibero-American Networks

What Happened?

The threat actor identified as Warlock (internally tracked by Microsoft as Storm-2603) has executed a strategic shift in its ransomware operations. Previously identified for its indiscriminate, global targeting strategy across nations like India, Japan, and the U.S., the group is now concentrating its efforts on large-scale organizations within Spanish- and Portuguese-speaking territories across Europe and Africa.

This campaign is notable for its utilization of complex zero-day exploit chains. Warlock operates alongside high-profile state-sponsored entities like APT27 and APT31, specifically targeting vulnerabilities inherent in on-premises SharePoint platforms.

Why It Matters

Warlock's transition from a scattershot global approach to a concentrated regional focus suggests a maturation in its victim-selection methodology. By targeting specific language-based markets, the group likely seeks to optimize its reconnaissance, lateral movement, and extortion tactics within localized business ecosystems. The reliance on zero-day vulnerabilities in critical infrastructure underscores a persistent security gap in legacy on-premises SharePoint deployments, which remain highly vulnerable to sophisticated intrusion despite available patches.

Key Details & Takeaways

  • Warlock utilizes specialized ToolShell exploit chains targeting on-premises SharePoint vulnerabilities.
  • Operational scope has moved from a broad global campaign to a localized focus on Spanish- and Portuguese-speaking organizations across Europe and Africa.
  • The group is currently identified as a distinct threat actor labeled Storm-2603, operating in parallel with established APTs like APT27 and APT31.