Warlock Ransomware Group Expands SharePoint Attacks on Critical Infrastructure Across Latin America and Iberia

Security researchers reported that a China-based threat group known as Warlock has been exploiting vulnerabilities in Microsoft SharePoint, including the “ToolShell” flaws disclosed in 2025 along with newer bugs patched in 2026, to break into critical infrastructure operators across Spanish- and Portuguese-speaking countries. According to reporting by The Record and other outlets, confirmed victims include a water utility, a telecommunications provider, a university and a regional government agency, with the campaign spanning targets across Europe, Africa and Latin America.

Once inside a network, the attackers reportedly conduct extensive reconnaissance before deploying tools designed to disable endpoint security products across multiple hosts, then install additional utilities built to blend in with legitimate administrator activity and avoid detection. Researchers at Symantec, cited in the reporting, said the group previously relied on the LockBit ransomware strain before switching to its own Warlock payload, and that unpatched SharePoint servers remain the primary entry point for the ongoing intrusions.

Microsoft has said it cannot tie the Chinese actors behind Warlock to any other state-sponsored group it already tracks, leaving open the question of whether the operation is financially motivated cybercrime, state-linked espionage, or some blend of the two, a distinction that has grown increasingly blurry among China-nexus hacking crews. The group has reportedly been active since before 2025 and has previously struck targets in the United States, Russia, Brazil, India, Taiwan and Japan.

Read the original report →