'Warlock' ransomware used in attacks on critical infrastructure in Portuguese, Spanish-speaking countries
A Chinese group is deploying Warlock ransomware against critical infrastructure via unpatched SharePoint flaws.
Symantec’s Threat Hunter Team says a China-based group is using Warlock ransomware against organizations in Portuguese- and Spanish-speaking countries across Europe, Africa, and Latin America, including a water utility, a telecommunications provider, a university, and a regional government. The attackers exploited Microsoft SharePoint vulnerabilities, including the 2025 ToolShell flaws and newer 2026 bugs recently highlighted by CISA, and in one case disabled security software on dozens of hosts before deploying ransomware. Microsoft previously could not tie the operators to another tracked Chinese state group and said they had used LockBit before switching to Warlock. Last year’s related SharePoint campaign was alleged to have hit at least 400 organizations, including the National Nuclear Security Administration, NIH, and DHS.