Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware
Executive Summary
Warlock, a China‑linked threat actor, continues to weaponize Microsoft SharePoint vulnerabilities—both legacy and newly discovered—to target organizations in Portuguese‑ and Spanish‑speaking countries. Symantec and Carbon Black’s Threat Hunter Team observed the group disabling security tools and deploying ransomware against critical infrastructure, government, and education entities.
Intelligence Metadata - Source Publisher: The Hacker News - Published Date: 2026-10-03T14:36:33+00:00 - Category: threat-intel
Original Description: The suspected China-linked threat actor known as Warlock is still continuing to weaponize Microsoft SharePoint vulnerabilities, likely both old and new, in attacks targeting organizations in Portuguese- and Spanish-speaking countries. The activity, observed by the Symantec and Carbon Black Threat Hunter Team, has hit critical infrastructure, government, and education organizations. "In the
"Bodily exercise, when compulsory, does no harm to the body; but knowledge which is acquired under compulsion obtains no hold on the mind."
— Plato