A Chinese threat group is reportedly deploying "Warlock" ransomware in attacks targeting critical infrastructure organizations in Portuguese and Spanish-speaking countries. The campaign exploits various vulnerabilities within Microsoft SharePoint, according to recent analysis from the Symantec Threat Hunter Team.
Victims identified in the ongoing attacks include a water utility, a telecommunications provider, a university, and a regional government, spanning locations across Europe, Africa, and Latin America. This activity extends a pattern of exploitation against SharePoint that Microsoft previously highlighted in 2025, when it warned of Chinese hackers using Warlock ransomware to target vulnerabilities colloquially known as "ToolShell."
The current campaign, observed continuing into 2026, also leverages newer SharePoint vulnerabilities recently flagged by the U.S. Cybersecurity and Infrastructure Security Agency (CISA). This indicates that organizations have not consistently applied patches for either the 2025 or the more recent 2026 SharePoint security flaws.
The focus on Portuguese and Spanish-speaking nations could suggest either opportunistic targeting of exposed, vulnerable SharePoint servers or a more deliberate strategic objective. The inclusion of critical infrastructure operators among the compromised entities underscores the potential for significant real-world disruption from successful ransomware attacks against essential services.
In one observed incident, attackers utilized a specialized tool to disable security software across dozens of hosts before deploying the Warlock ransomware. The threat actors conducted extensive reconnaissance on compromised systems, installing various tools designed to camouflage their activities by mimicking normal traffic typically originating from developer or administrator workstations.
SharePoint remains a high-value target for both financially motivated and state-sponsored groups seeking intelligence, given its common use for storing confidential documents and its deep integration with Microsoft's authentication services. A successful foothold in SharePoint can enable attackers to penetrate deeper into victim networks.
Last year, a hacking campaign against SharePoint instances caused widespread concern after numerous prominent organizations were breached through these vulnerabilities. Reports indicated that at least 400 governments and businesses were allegedly compromised, including the National Nuclear Security Administration, the National Institutes of Health, and the Department of Homeland Security. Additionally, several Swiss government institutions were attacked via SharePoint vulnerabilities in August of last year.
Microsoft has not publicly linked the Chinese group behind Warlock to any other tracked state-backed Chinese groups, though it noted last year that the hackers initially used a strain of LockBit ransomware before transitioning to Warlock. Previous Warlock ransomware attacks have been documented against organizations in the U.S., Russia, Brazil, India, Taiwan, and Japan.






