Warlock Ransomware Targets Critical Infrastructure in Spanish and Portuguese-Speaking Nations via SharePoint Exploits
A Chinese threat actor group is actively deploying the **Warlock** ransomware against critical infrastructure organizations in Portuguese- and Spanish-speaking countries. The attackers are leveraging a range of vulnerabilities within **Microsoft SharePoint**, with victims spanning water utilities, telecommunications providers, universities, and regional governments across Europe, Africa, and Latin America.
A new report from the **Symantec Threat Hunter Team** reveals an ongoing campaign by a Chinese-linked group utilizing the **Warlock** ransomware. This sophisticated operation primarily targets critical infrastructure in Portuguese- and Spanish-speaking regions, exploiting known and newly identified vulnerabilities in **Microsoft SharePoint**.
### Escalating SharePoint Exploitation
Last year, **Microsoft** issued a warning about China-based hackers using **Warlock** to exploit **SharePoint** vulnerabilities, colloquially known as βToolShell.β **Symantec** researchers confirm these attacks have persisted into 2026, now incorporating newer **SharePoint** vulnerabilities recently highlighted by the **U.S. Cybersecurity and Infrastructure Security Agency (CISA)**.
The continued success of these attacks underscores a critical failure in patching practices, as many **SharePoint** deployments remain vulnerable to both 2025 and 2026 exploits.
### Strategic Targeting and Advanced Tactics
**Symantec** researchers suggest the focus on Portuguese- and Spanish-speaking countries could be either opportunistic, driven by exposed vulnerable **SharePoint** servers, or a more deliberate strategic choice. The inclusion of critical infrastructure operators among the victims emphasizes the severe real-world consequences ransomware attacks can have on essential services.
In one incident, the attackers employed a specialized tool to disable security software across dozens of hosts before deploying the **Warlock** ransomware. They also conducted extensive reconnaissance on compromised systems, installing various tools designed to camouflage their activities within normal network traffic, often mimicking developer or administrator workstations.
### CISA's Warning and Broader Implications
This report closely follows a **CISA** alert from a month prior, which warned of hackers exploiting six new **SharePoint** vulnerabilities that grant attackers broad access to organizational networks.
**SharePoint** remains a prime target for both financially motivated cybercriminals and state-sponsored groups seeking intelligence. Its role in storing confidential documents and its deep integration with **Microsoft**'s authentication services make it a crucial gateway for skilled attackers to penetrate deeper into victim networks.
Previous campaigns against **SharePoint** instances have caused widespread alarm, with several prominent organizations globally being breached through these vulnerabilities. This includes the **National Nuclear Security Administration**, the **National Institutes of Health**, and the **Department of Homeland Security**, with an estimated 400 governments and businesses affected. Swiss government institutions were also targeted last year through **SharePoint** vulnerabilities.
While **Microsoft** has not definitively linked the Chinese group behind **Warlock** to other known state-backed groups, it noted the hackers initially used a strain of **LockBit** ransomware before switching to **Warlock**. Historically, **Warlock** has been deployed against organizations in the U.S., Russia, Brazil, India, Taiwan, and Japan.