'Warlock' ransomware used in attacks on critical infrastructure in Portuguese, Spanish-speaking countries
Critical infrastructure organizations in Portuguese- and Spanish-speaking countries are being attacked by a Chinese group using a ransomware strain called Warlock.
The group is exploiting a variety of vulnerabilities impacting Microsoft SharePoint, according to a new report from Symantec Threat Hunter Team.
Symantec researchers said the victims include a water utility, a telecommunications provider, a university and a regional government. The organizations are located across Europe, Africa and Latin America.
Last year, Microsoft warned that China-based hackers using the Warlock ransomware were focusing their attacks on SharePoint vulnerabilities colloquially named “ToolShell.”
Symantec found that the attacks have continued into 2026 and now include newer SharePoint vulnerabilities recently spotlighted by the U.S. government.
The campaign illustrated that hackers are still finding success in exploiting SharePoint deployments that have not been patched either for the 2025 vulnerabilities or the 2026 bugs.
“The apparent recent focus on Portuguese- and Spanish-speaking countries suggests either an opportunistic targeting pattern driven by exposed, vulnerable SharePoint servers, or a more deliberate tasking,” Symantec researchers said. “The inclusion of critical infrastructure operators among the victims is a reminder of the potential real-world consequences of ransomware attacks that succeed against essential services.”
In one incident, Symantec found the attackers used a tool built to disable security software on dozens of hosts before deploying the Warlock ransomware.
The attackers carried out extensive reconnaissance on compromised systems, installing a variety of tools designed to blend their activities into normal traffic that typically came from developer or administrator workstations.
The report comes one month after the U.S. Cybersecurity and Infrastructure Security Agency (CISA) published a warning that hackers are exploiting six new SharePoint vulnerabilities providing attackers with wide access to organizations.
SharePoint is a prime target for both financially-motivated hackers as well as state-sponsored groups seeking intelligence. The service is often used to store confidential documents and is deeply integrated with Microsoft’s authentication services, meaning skillful enough hackers could use a foothold there to burrow deeper into their victims’ networks.
Last year’s hacking campaign against SharePoint instances caused global alarm after several prominent organizations were breached through the vulnerabilities. At least 400 governments and businesses were allegedly breached, including the National Nuclear Security Administration, the National Institutes of Health and the Department of Homeland Security.
In August, several Swiss government institutions were also attacked through SharePoint vulnerabilities.
Last year, Microsoft could not tie the Chinese group behind Warlock to any other Chinese state-backed group it tracks, only noting that the hackers used a strain of the LockBit ransomware before switching to Warlock.
Warlock had previously been used against organizations in the U.S., Russia, Brazil, India, Taiwan and Japan.
Jonathan Greig
is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.



