Warlock Group Exploits SharePoint to Deploy Ransomware in Lusophone and Hispanic Regions

Medium · The Hacker News ·

Exploited

Key points

  • Warlock, a China-linked suspect, is exploiting SharePoint vulnerabilities.
  • The campaign disables security tools from Microsoft, Symantec, and Carbon Black.
  • Ransomware is deployed against government, education, and critical infrastructure.
  • Targets are in Portuguese- and Spanish-speaking countries as of October 2026.
  • No CVE identifiers have been assigned yet.

In October 2026, a threat actor tracked as Warlock, suspected of ties to China, launched a campaign that leverages flaws in Microsoft SharePoint. The group uses these vulnerabilities to gain initial access, then disables endpoint protection tools from Microsoft, Symantec, and Carbon Black. After neutralizing defenses, it deploys ransomware.

The operation has been observed across countries where Portuguese and Spanish are primary languages. Targets include government agencies, educational institutions, and critical infrastructure operators. This broad scope suggests the actor is not limiting itself to a single sector.

By disrupting security tooling before encrypting systems, Warlock increases the likelihood of successful ransomware deployment and reduces the time defenders have to respond. The involvement of a China-linked suspect raises geopolitical concerns, though attribution remains preliminary.

SharePoint is widely used for collaboration and document management, making it an attractive initial access vector. The absence of assigned CVEs means defenders cannot rely on standard vulnerability identifiers for detection or patching guidance.

Security teams should monitor for unusual SharePoint activity, unexpected disabling of antivirus or EDR agents, and ransomware precursors. Organizations in the affected regions and sectors should prioritize hardening SharePoint and ensuring offline backups.

What to do now

  1. Immediately audit SharePoint servers for known vulnerabilities and apply all available Microsoft patches.
  2. Verify that Microsoft Defender, Symantec, and Carbon Black agents are running and tamper protection is enabled.
  3. Restrict SharePoint access to least privilege and enforce MFA for all administrative accounts.
  4. Monitor logs for signs of security tool disabling, such as service stops or registry changes.
  5. Isolate and segment critical infrastructure and government networks from general IT.
  6. Ensure offline, immutable backups are in place and test restoration procedures.
  7. Conduct phishing and ransomware tabletop exercises for education and government staff.

Original source

The Hacker News

Original AI-assisted analysis, sources cited. Verify with the vendor advisory before acting.

← All cyber news