'Warlock' ransomware used in attacks on critical infrastructure in Portuguese, Spanish-speaking countries
What happened
Last year, Microsoft warned that China-based hackers using the Warlock ransomware were focusing their attacks on SharePoint vulnerabilities colloquially named “ToolShell.” Symantec found that the attacks have continued into 2026 and now include newer SharePoint vulnerabilities recently spotlighted by the U.S.
The campaign illustrated that hackers are still finding success in exploiting SharePoint deployments that have not been patched either for the 2025 vulnerabilities or the 2026 bugs. In one incident, Symantec found the attackers used a tool built to disable security software on dozens of hosts before deploying the Warlock ransomware.
The group is exploiting a variety of vulnerabilities impacting Microsoft SharePoint, according to a new report from Symantec Threat Hunter Team. Symantec researchers said the victims include a water utility, a telecommunications provider, a university and a regional government. The organizations are located across Europe, Africa and Latin America.
Key facts
- Symantec — found: that the attacks have continued into 2026 and now include newer SharePoint vulnerabilities recently spotlighted by the U.S
- In one incident, Symantec — found: the attackers used a tool built to disable security software on dozens of hosts before deploying the Warlock ransomware
Sources & evidence
- The Record Reporting source
'Warlock' ransomware used in attacks on critical infrastructure in Portuguese, Spanish-speaking countries ↗
https://therecord.media/warlock-ransomware-used-in-critical-infrastructure-attacks