Dark Reading reports that Warlock ransomware has struck large organizations in Spain and Portugal. The threat actor behind it is about a year old and associated with China, but it does not behave like a typical ransomware operation.
Warlock appears to be a cybercrime gang on the surface, while operating more like a state-associated advanced persistent threat. That hybrid profile makes defense and attribution harder, because the attackers may be pursuing goals beyond simple financial gain.
The report says the campaign is hitting organizations in unexpected places, suggesting deliberate targeting rather than opportunistic scanning. This is a single-source account, so no independent reports are available to compare or contradict its findings.