Skip to content
feed: live
>_0dayNews
ransomware
● Breaking

Chinese APT Warlock Ransomware Targets Iberia

Chinese threat actor Warlock has hit large organizations in Spain and Portugal, operating more like a state-linked APT than a typical criminal crew.

Chinese APT Warlock Ransomware Targets Iberia
Image: AI-generated — no human photographer / 0dayNews AI Cover · Generated on-site infrastructure — no external license
airgapMorgan "airgap" Reyes·Published ·1 min read

A Chinese threat actor tracked as Warlock has conducted ransomware attacks against large organizations in Spain and Portugal, per DarkReading reporting published October 1. Warlock has been active roughly one year.

The notable detail is not the ransomware tooling. DarkReading characterizes Warlock’s operational profile as consistent with a state-associated APT rather than a conventional financially motivated crew: patient targeting, discipline not typical of RaaS affiliates, and a geographic focus unusual for Chinese state-linked operations. Attribution confidence: single source, not independently corroborated. Treat accordingly.

Target profile

Spain and Portugal, large organizations. No victim names published. Scope outside Iberia is unconfirmed.

Operational behavior

DarkReading’s characterization places Warlock at an atypical intersection: ransomware tooling and an extortion playbook on the surface, with tradecraft more consistent with state-sponsored actors underneath. The publication describes Warlock as behaving like a state-associated APT while appearing externally like a cybercrime operation.

Analysis: Chinese state-linked actors have historically prioritized intelligence collection over financial extortion. A crew that inverts this profile is either a contractor, a group with unusual state adjacency, or a misattribution. None of these can be ruled out on current reporting.

No formal government attribution has been published. No CISA advisory, no Europol statement, no joint advisory from Spanish or Portuguese national CERTs, as of this writing.

What is not confirmed

Specific tooling, ransom amounts, victim identities, TTPs beyond the behavioral description, and any connections to documented Chinese APT families (APT40, APT41, Volt Typhoon) are not confirmed in available reporting.

Context

KillSec was dismantled this week: Operation KillSwitch Dismantles KillSec Ransomware RaaS. Ransomware targeting of manufacturers accelerated sharply in H1 2026: Ransomware Attacks on Manufacturers Up 40% in H1 2026. CISA has separately flagged ransomware gangs exploiting unpatched infrastructure: CISA: Ransomware Gangs Exploiting TeamCity RCE Flaw.

Found this useful? Share it.