What happened

A China-linked group is using a ransomware strain called Warlock to attack critical infrastructure organisations in Portuguese and Spanish-speaking countries, according to research from Symantec's Threat Hunter Team. The victims named in the reporting include a water utility, a telecommunications provider, a university and a regional government, spread across Europe, Africa and Latin America.

The entry point is Microsoft SharePoint. The group is exploiting a range of vulnerabilities in the platform, including the 2025 flaws that Microsoft and others nicknamed ToolShell, as well as newer SharePoint bugs the U.S. government recently highlighted. Symantec says the campaign continued into 2026 and that the attackers are still succeeding against SharePoint deployments that were never patched for either the 2025 or the 2026 issues.

In one incident the attackers used a tool built to disable security software on dozens of hosts before deploying the ransomware. They carried out extensive reconnaissance on compromised systems and installed a variety of tools designed to blend in with normal traffic from developer or administrator workstations.

Symantec's own summary is careful about motive. The reported focus on Portuguese and Spanish-speaking countries suggests either opportunistic targeting of exposed, vulnerable SharePoint servers or more deliberate tasking. The researchers add that including critical infrastructure operators among the victims is a reminder of the real-world consequences when ransomware succeeds against essential services. The report lands about a month after CISA warned that hackers were exploiting six new SharePoint vulnerabilities. SharePoint is a prized target because organisations store confidential documents there and because it is tightly integrated with Microsoft's authentication services, so a foothold can open a path deeper into a network.

Why this is a GRC story

Patching is a governance decision, not a maintenance task. These are known vulnerabilities. The question an unpatched internet-facing system raises is who accepted the risk, on what evidence, and when it was last reviewed. If no one can answer that, the control was never really in place.

Concentration risk deserves a number. A platform that holds documents and anchors authentication fails in more than one direction at once. That combination is what turns a single unpatched bug into an enterprise-wide incident.

Tamper protection is worth verifying. Attackers disabling security software across dozens of hosts is a familiar step, and it only works when endpoint protection can be switched off from the endpoint itself. Testing that assumption is cheap, and the result is either a fix or a documented, owned risk.

What to watch

Watch whether the 2026 SharePoint issues see the same exploitation wave as last year's. Last year's campaign reportedly touched hundreds of governments and businesses, including U.S. agencies. Repeat waves tend to follow whichever servers stayed unfixed.

The practical move is to inventory every internet-facing SharePoint instance, including ones owned by teams that do not think of themselves as running a server, and match each one to a patch record. Anything that cannot be matched, or that is deliberately patched late, belongs on a risk register with a named owner and an expiry date.

Attribution: Analysis based on The Record's reporting and Symantec's research. This article is original commentary, not a repost of the source material.

More daily case studies
← Back to GRC News