Cyber — 2026-10-06

China-Linked Warlock Ransomware Group Exploits SharePoint Flaws to Hit Critical Infrastructure in Latin America

BLUFWarlock's active exploitation of unpatched SharePoint servers leaves Latin American critical infrastructure exposed, though whether the group will publicly claim a new victim in the region by year-end remains genuinely uncertain.

Symantec and Carbon Black's Threat Hunter Team reported that the suspected China-linked Warlock group, also tracked as Longlegs and Storm-2603, is exploiting Microsoft SharePoint vulnerabilities against critical infrastructure, government, and education targets in Portuguese- and Spanish-speaking countries 12. The Record reported that victims include a water utility, a telecommunications provider, a university, and a regional government across Europe, Africa, and Latin America 3. In one incident, attackers disabled security software on dozens of hosts before deploying the ransomware 3. SC Media, relaying Dark Reading, reported the group staged the payload in the domain's SYSVOL share so Active Directory replication spread it to domain controllers 2. The Record reported that the campaign now includes newer SharePoint flaws CISA flagged a month earlier 3.

Analysis
Warlock retains active SharePoint access, so unpatched servers in Portuguese- and Spanish-speaking countries stay exposed. Whether the group will publicly claim at least one new Latin American victim by year-end is genuinely uncertain. Its targets span a water utility, a telecommunications provider, a university and a regional government, but nothing shows whether this reflects deliberate tasking or opportunistic scanning. Victims who pay quietly would never reach a leak site, which limits what public claims can reveal. Confidence is low because everything traces to one vendor's telemetry, Symantec's Threat Hunter Team, which the trade press only amplifies. The Latin American concentration may simply track where vulnerable servers are exposed, and Warlock could shift regions once a new exploit chain appears. A claimed victim would push regional operators to patch and hunt for SYSVOL-staged payloads at once. Silence would not show the exposure has closed.
5 sources
  1. Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware - The Hacker News
  2. Chinese ransomware group Warlock targets Spanish- and Portuguese-speaking countries - SC Media
  3. 'Warlock' ransomware used in attacks on critical infrastructure in Portuguese, Spanish-speaking countries - The Record (Recorded Future News)
  4. Warlock Expands SharePoint Exploitation in Critical Infrastructure Attacks - SecurityWeek
  5. Warlock Ransomware Attackers Hit Water and Telecom Operators - Symantec (Broadcom) Threat Hunter Team

View in full brief →

UNCLASSIFIED // OPEN SOURCE