
Chinese Operators Deploy Warlock Ransomware Against Unpatched SharePoint in Iberian and Latin American Critical Infrastructure
A Chinese group using Warlock ransomware has sustained attacks on critical infrastructure SharePoint servers across Portuguese- and Spanish-speaking countries into 2026. Symantec evidence shows deliberate tooling to evade detection and extensive reconnaissance before encryption. The campaign highlights persistent gaps in patching high-value collaboration platforms despite repeated government warnings.
Symantec traced the intrusions to a Chinese group that first gained footholds through SharePoint vulnerabilities labeled ToolShell in 2025 and continued into 2026 with newly disclosed bugs. Attackers disabled security tooling on dozens of hosts, performed extended reconnaissance using developer workstation traffic as cover, then deployed Warlock. Victims span Europe, Africa, and Latin America, confirming the shift from earlier U.S., Russian, and Asian targets.
The pattern aligns with CISA's June 2026 advisory on six SharePoint flaws and Microsoft's prior attribution of the same actors switching from LockBit to Warlock. SharePoint's deep integration with authentication services makes it an efficient pivot point for both ransomware and intelligence collection, explaining repeated success against critical infrastructure that delayed patching.
Operational significance lies in the selective geographic focus: either opportunistic scanning of exposed servers or deliberate tasking. Continued exploitation one month after the CISA alert indicates patch adoption rates remain insufficient. Next indicators will appear in procurement records for emergency incident response contracts or new victim disclosures from the same regions within 60-90 days.
Symantec: Warlock operators will expand to additional unpatched SharePoint instances in Africa and Latin America within 90 days, exceeding 50 victims if current reconnaissance patterns persist.
Sources (3)
- [1]Symantec Threat Hunter Team Report on Warlock(https://symantec.com/blogs/threat-intelligence/warlock-ransomware-sharepoint)
- [2]CISA Advisory AA26-XXX on SharePoint Vulnerabilities(https://www.cisa.gov/news/2026/06/sharepoint-exploitation)
- [3]Microsoft Security Blog on Chinese Actor ToolShell Activity(https://www.microsoft.com/security/blog/2025/09/toolshell-sharepoint)