Skip to main content
MicrosoftSecurity incident

'Warlock' ransomware used in attacks on critical infrastructure in Portuguese, Spanish-speaking countries

What happened

Multiple vulnerabilities in Microsoft SharePoint are being exploited by a Chinese hacking group using Warlock ransomware to attack critical infrastructure organizations.

Source

Article excerpt

Highlighted: the sentence this signal was extracted from

Critical infrastructure organizations in Portuguese- and Spanish-speaking countries are being attacked by a Chinese group using a ransomware strain called Warlock. The group is exploiting a variety of vulnerabilities impacting Microsoft SharePoint, according to a new report from Symantec Threat Hunter Team. Symantec researchers said the victims include a water utility, a telecommunications provider, a university and a regional government. The organizations are located across Europe, Africa and Latin America. Last year, Microsoft warned that China-based hackers using the Warlock ransomware were focusing their attacks on SharePoint vulnerabilities colloquially named "ToolShell." Symantec found that the attacks have continued into 2026 and now include newer SharePoint vulnerabilities recently spotlighted by the U.S. government. The campaign illustrated that hackers are still finding success in exploiting SharePoint deployments that have not been patched either for the 2025 vulnerabilities or the 2026 bugs. "The apparent recent focus on Portuguese- and Spanish-speaking countries suggests either an opportunistic targeting pattern driven by exposed, vulnerable SharePoint servers, or a more deliberate tasking," Symantec researchers said. "The inclusion of critical infrastructure operators among the victims is a reminder of the potential real-world consequences of ransomware attacks...

Keep reading with a free account

The rest of this article, and every signal for Microsoft, is in your free account.

Extracted by Autobound

From the Signal API record
Event
Security incident

What this signalsA breach often leads to new security spend.

Product
SharePoint

More security incident signals at other companies

The full record

From the Signal API record

Details

Issue named
Multiple vulnerabilities, including those colloquially named “ToolShell” and others spotlighted by CISA, are being exploited by a Chinese group using Warlock ransomware.

Topics and mentions

Product tags

  • online technology
  • general technology
  • data

Extraction

Confidence
90%
Detected
Oct 2, 2026
signal_type
news
signal_subtype
security_incident

Use this data

Get every security incident signal for Microsoft and the companies you sell to, in the tools you already use.

  1. Ask Claude about it

    Connect Autobound to Claude, Claude Code or Cursor with MCP. Then ask: “What changed at Microsoft this week?”

  2. Send it to your own tools

    The Signal API returns security incident signals for any list of companies as JSON, for your CRM, warehouse or app.

  3. Try it free

    Sign up and spend your free credits on the companies you sell to.

    Start Free1,000 free credits

The API returns more than this page shows

This page shows a preview. The full news record in the Signal API and MCP can also have these 8 fields. Some fields are empty for some signals.

Company

  • linkedin_urlValue in the API
  • industriesValue in the API
  • employee_count_lowValue in the API
  • employee_count_highValue in the API
  • revenueValue in the API
  • descriptionValue in the API

Signal

  • signal_nameValue in the API
  • associationValue in the API
Show the full JSONThe record on this page and the API request

GET /v1/signals/87b05972-898a-8cb5-b795-5ff45d23dd83 returns this record as JSON. POST /v1/companies/enrich returns every signal for microsoft.com.

{
  "signal_id": "87b05972-898a-8cb5-b795-5ff45d23dd83",
  "signal_type": "news",
  "signal_subtype": "security_incident",
  "detected_at": "2026-10-02T14:05:00+00:00",
  "company": {
    "name": "Microsoft",
    "domain": "microsoft.com"
  },
  "data": {
    "url": "https://therecord.media/warlock-ransomware-used-in-critical-infrastructure-attacks",
    "title": "'Warlock' ransomware used in attacks on critical infrastructure in Portuguese, Spanish-speaking countries",
    "excerpt": "Critical infrastructure organizations in Portuguese- and Spanish-speaking countries are being attacked by a Chinese group using a ransomware strain called Warlock. The group is exploiting a variety of vulnerabilities impacting Microsoft SharePoint, according to a new report from Symantec Threat Hunter Team. Symantec researchers said the victims include a water utility, a telecommunications provider, a university and a regional government. The organizations are located across Europe, Africa and Latin America. Last year, Microsoft warned that China-based hackers using the Warlock ransomware were focusing their attacks on SharePoint vulnerabilities colloquially named “ToolShell.” Symantec found that the attacks have continued into 2026 and now include newer SharePoint vulnerabilities recently spotlighted by the U.S. government. The campaign illustrated that hackers are still finding success in exploiting SharePoint deployments that have not been patched either for the 2025 vulnerabilities or the 2026 bugs. “The apparent recent focus on Portuguese- and Spanish-speaking countries suggests either an opportunistic targeting pattern driven by exposed, vulnerable SharePoint servers, or a more deliberate tasking,” Symantec researchers said. “The inclusion of critical infrastructure operators among the victims is a reminder of the potential real-world consequences of ransomware attacks...",
    "product": "SharePoint",
    "summary": "Multiple vulnerabilities in Microsoft SharePoint are being exploited by a Chinese hacking group using Warlock ransomware to attack critical infrastructure organizations.",
    "planning": false,
    "image_url": "https://cms.therecord.media/uploads/moshed_10_02_10_8_51_fb7e436dcd.png",
    "confidence": 0.9,
    "product_data": {
      "name": "SharePoint",
      "full_text": "Microsoft SharePoint",
      "fuzzy_match": false
    },
    "product_tags": [
      "online_technology",
      "general_technology",
      "data"
    ],
    "published_at": "2026-10-02T14:05:00Z",
    "vulnerability": "Multiple vulnerabilities, including those colloquially named “ToolShell” and others spotlighted by CISA, are being exploited by a Chinese group using Warlock ransomware.",
    "article_sentence": "The group is exploiting a variety of vulnerabilities impacting Microsoft SharePoint, according to a new report from Symantec Threat Hunter Team."
  }
}

Long text fields are shortened on this page.

Looking up one signal by its id is free. Enrich costs 2 credits per signal returned; a call with no results is free.