Warlock Ransomware Group Still Exploiting SharePoint Flaws to Blind Security Tools, Target LATAM/Iberian Organizations
According to reporting from Symantec and Carbon Black's Threat Hunter Team, via The Hacker News, the suspected China-linked threat actor known as Warlock continues to weaponize Microsoft SharePoint vulnerabilities — likely a mix of older and newer flaws — in ongoing intrusions. The campaign is reportedly focused on organizations in Portuguese- and Spanish-speaking countries, with victims spanning critical infrastructure, government, and education sectors. Warlock's playbook reportedly includes disabling security tooling on compromised hosts before deploying ransomware.
Why It Matters
SharePoint is a high-value target because it typically sits at the center of document workflows and often has broad internal trust, making it an efficient initial-access and lateral-movement foothold. A threat actor capable of both exploiting SharePoint vulnerabilities and reliably disabling endpoint security products before detonating ransomware represents a serious threat to availability and data confidentiality for affected organizations — particularly in the critical infrastructure, government, and education sectors called out in this reporting. Organizations running on-premises or hybrid SharePoint deployments in the targeted regions should treat this as an active, credible threat.
What Defenders Should Watch For
- Audit and harden all internet-facing or internally-exposed SharePoint servers; prioritize patch currency, since the reporting suggests both old and new SharePoint flaws are in use.
- Monitor for anomalous SharePoint worker-process activity (e.g.,
w3wp.exespawning unexpected child processes), unusual IIS/SharePoint log entries, and webshell-style file drops in SharePoint web directories. - Alert on attempts to tamper with or disable EDR/AV services — service stops, driver unloads, Defender exclusion changes, or tasklist/process-kill activity targeting known security agents — as this is reported as a precursor step before ransomware deployment.
- Watch for rapid, high-volume file modification/encryption activity following any SharePoint-adjacent compromise, and ensure backups are isolated and tested given the ransomware end-state.
- Review SharePoint admin and service account activity for unusual authentication patterns or privilege escalation, especially from regions or sectors matching this campaign's reported targeting.
This is developing intelligence based on a single vendor report, and specific CVEs, indicators, and technical exploitation details were not fully available at the time of writing. Detection content will be added here as more specifics emerge. Read the original reporting at The Hacker News.