← Back to blog

Warlock Hacker Group Targets SharePoint to Deploy Ransomware

China-linked Warlock group exploits SharePoint flaws to disable security tools and deploy ransomware. Targets critical infrastructure in Portuguese- and Spanish-speaking regions.

TL;DR

  • Warlock, a suspected China-linked APT, actively exploits Microsoft SharePoint vulnerabilities.
  • Attacks disable security tools before deploying ransomware payloads.
  • Critical infrastructure, government, and education sectors in Iberian regions are primary targets.
  • Symantec and Carbon Black Threat Hunter Team tracked ongoing campaign activity.
  • Organizations should audit SharePoint instances and enforce strict access controls immediately.

A suspected Chinese state-sponsored threat actor known as Warlock continues to exploit vulnerabilities in Microsoft SharePoint to infiltrate high-value targets. These attacks primarily affect organizations in Portuguese- and Spanish-speaking countries, including those in critical infrastructure, government, and education sectors.

According to joint research from Symantec and the Carbon Black Threat Hunter Team, Warlock's methods involve disabling existing security tools before deploying ransomware. This layered approach allows attackers to maintain persistent access while evading detection and maximizing impact.

Attack Vector and Tactics

  • Warlock leverages both known and potentially zero-day SharePoint vulnerabilities for initial access.
  • Once inside, attackers systematically disable endpoint protection and other monitoring tools.
  • Lateral movement follows, often using legitimate administrative tools to avoid suspicion.
  • Ransomware deployment occurs only after establishing deep network presence and data exfiltration.

Defensive Recommendations

  • Organizations should patch SharePoint servers immediately and monitor for unusual admin activity.
  • Restrict access to SharePoint admin panels using multi-factor authentication and least privilege principles.
  • Deploy behavioral analytics to detect tool tampering or unexpected encryption activities.
  • Conduct regular penetration testing focused on web application and collaboration platform entry points.

Sources

Sources

Security email updates

One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.