Warlock ransomware hits Portuguese- and Spanish-speaking infrastructure through SharePoint flaws
Symantec says the China-linked group behind Warlock ransomware targeted at least four organisations across Europe, Africa and Latin America, including a water utility, a telecoms provider, a university and a regional government. The attacks exploited vulnerabilities in on-premises Microsoft SharePoint servers, underscoring the risks for European essential services still running unpatched systems.
Bottom line — Symantec found attackers disabled security software on at least 40 hosts before deploying Warlock on at least 33.
Go deeper 5
-
Symantec says the campaign continued into 2026 and used newer SharePoint vulnerabilities alongside flaws first exploited in 2025.
-
In one intrusion, attackers used a tool to disable security software on at least 40 hosts within about two hours, then deployed ransomware on at least 33.
-
According to Symantec, the group staged ransomware in the domain’s SYSVOL share, allowing normal domain replication to distribute it across machines.
-
The researchers say attackers used legitimate tools and Visual Studio Code’s tunnelling feature to make reconnaissance and remote access resemble normal administrator or developer activity.
-
Symantec says the group’s focus on Portuguese- and Spanish-speaking countries could reflect opportunistic targeting of exposed servers or more deliberate tasking.