Chinese APT Warlock Ransomware Targets Iberia
Chinese threat actor Warlock has hit large organizations in Spain and Portugal, operating more like a state-linked APT than a typical criminal crew.

A Chinese threat actor tracked as Warlock has conducted ransomware attacks against large organizations in Spain and Portugal, per DarkReading reporting published October 1. Warlock has been active roughly one year.
The notable detail is not the ransomware tooling. DarkReading characterizes Warlock’s operational profile as consistent with a state-associated APT rather than a conventional financially motivated crew: patient targeting, discipline not typical of RaaS affiliates, and a geographic focus unusual for Chinese state-linked operations. Attribution confidence: single source, not independently corroborated. Treat accordingly.
Target profile
Spain and Portugal, large organizations. No victim names published. Scope outside Iberia is unconfirmed.
Operational behavior
DarkReading’s characterization places Warlock at an atypical intersection: ransomware tooling and an extortion playbook on the surface, with tradecraft more consistent with state-sponsored actors underneath. The publication describes Warlock as behaving like a state-associated APT while appearing externally like a cybercrime operation.
Analysis: Chinese state-linked actors have historically prioritized intelligence collection over financial extortion. A crew that inverts this profile is either a contractor, a group with unusual state adjacency, or a misattribution. None of these can be ruled out on current reporting.
No formal government attribution has been published. No CISA advisory, no Europol statement, no joint advisory from Spanish or Portuguese national CERTs, as of this writing.
What is not confirmed
Specific tooling, ransom amounts, victim identities, TTPs beyond the behavioral description, and any connections to documented Chinese APT families (APT40, APT41, Volt Typhoon) are not confirmed in available reporting.
Context
KillSec was dismantled this week: Operation KillSwitch Dismantles KillSec Ransomware RaaS. Ransomware targeting of manufacturers accelerated sharply in H1 2026: Ransomware Attacks on Manufacturers Up 40% in H1 2026. CISA has separately flagged ransomware gangs exploiting unpatched infrastructure: CISA: Ransomware Gangs Exploiting TeamCity RCE Flaw.
Found this useful? Share it.


