A water utility and a major telecommunications provider are among the latest victims of the Warlock ransomware group, which has intensified its focus on critical infrastructure. Recent security analysis reveals that the group is increasingly targeting organizations across three continents, specifically focusing on Portuguese- and Spanish-speaking regions including Europe, Africa, and Latin America.
According to researchers at Symantec and Microsoft, Warlock’s latest campaign demonstrates a high level of technical sophistication. The group utilizes a specialized exploit chain known as “ToolShell” to gain initial access. This chain specifically targets vulnerabilities in Microsoft SharePoint, allowing the attackers to bypass perimeter security and establish a foothold within enterprise collaboration environments. Beyond infrastructure, the group has also compromised regional government bodies and academic institutions.
Warlock, which is also tracked by security firms under the aliases Longlegs, Storm-2603, and GOLD SALEM, is characterized by its hybrid operational model. While its primary visible goal is financial extortion through ransomware, its tactics often mirror state-level espionage. Analysts have linked the group to China-nexus threat actors, noting a blend of targeted data theft and traditional criminal extortion. The group originally surfaced using LockBit ransomware variants before transitioning to its own custom-developed operational tools.
Advanced Defense Evasion and BYOVD Tactics
One of the more aggressive aspects of Warlock’s toolkit is its approach to neutralizing security software. The attackers frequently employ the “Bring Your Own Vulnerable Driver” (BYOVD) technique. This involves the intentional deployment of legitimate but vulnerable drivers onto a target system to gain kernel-level privileges. Specifically, Warlock has been observed abusing drivers associated with Huorong Antivirus to systematically disable Endpoint Detection and Response (EDR) systems.
By killing security processes before deploying the final ransomware payload, the group significantly reduces the likelihood of early detection. This methodical “EDR-killing” process is often followed by the use of custom scripts to exfiltrate sensitive data, which is then used as leverage in double-extortion demands.
Technical indicators provided by Broadcom (Symantec) suggest that administrators should prioritize patching SharePoint servers and monitoring for the unauthorized loading of third-party drivers, particularly those not natively required by the local environment. Because the group’s focus remains largely on Lusophone and Hispanophone organizations, IT teams in these linguistic regions are advised to implement heightened monitoring for ToolShell-related activity and atypical administrative behavior within SharePoint logs.
