'Warlock' ransomware used in attacks on critical infrastructure in Portuguese, Spanish-speaking countries
Article excerpt
Highlighted: the sentence this signal was extracted from
Critical infrastructure organizations in Portuguese- and Spanish-speaking countries are being attacked by a Chinese group using a ransomware strain called Warlock. The group is exploiting a variety of vulnerabilities impacting Microsoft SharePoint, according to a new report from Symantec Threat Hunter Team. Symantec researchers said the victims include a water utility, a telecommunications provider, a university and a regional government. The organizations are located across Europe, Africa and Latin America. Last year, Microsoft warned that China-based hackers using the Warlock ransomware were focusing their attacks on SharePoint vulnerabilities colloquially named "ToolShell." Symantec found that the attacks have continued into 2026 and now include newer SharePoint vulnerabilities recently spotlighted by the U.S. government. The campaign illustrated that hackers are still finding success in exploiting SharePoint deployments that have not been patched either for the 2025 vulnerabilities or the 2026 bugs. "The apparent recent focus on Portuguese- and Spanish-speaking countries suggests either an opportunistic targeting pattern driven by exposed, vulnerable SharePoint servers, or a more deliberate tasking," Symantec researchers said. "The inclusion of critical infrastructure operators among the victims is a reminder of the potential real-world consequences of ransomware attacks...
Keep reading with a free account
The rest of this article, and every signal for Microsoft, is in your free account.
