Warlock Ransomware Exploits Unpatched SharePoint Vulnerabilities in Critical Infrastructure Across Portuguese‑ and Spanish‑Speaking Nations
What Happened – A China‑based threat group has been using the Warlock ransomware to compromise critical‑infrastructure operators in Portuguese‑ and Spanish‑speaking countries. The attackers repeatedly exploit unpatched Microsoft SharePoint flaws (including the “ToolShell” chain and newer 2025‑2026 vulnerabilities) to gain footholds, disable security tools, and deploy ransomware.
Why It Matters for Trust & Control Assurance
- Demonstrates the risk of inadequate vulnerability‑management and patch‑remediation – a core control objective that continuous‑control programs are built to enforce and evidence.
- Highlights the need for defensible audit evidence that SharePoint instances are regularly scanned, patched, and that remediation actions are logged.
- Aligns with the Control Mapping capability, which helps organizations collect, correlate, and present remediation evidence across frameworks.
Who Is Affected – Water utilities, telecommunications providers, universities, and regional governments across Europe, Africa, and Latin America.
Recommended Actions
- Inventory all SharePoint deployments and verify they are patched against the 2025‑2026 advisories.
- Deploy automated vulnerability scanning and integrate findings into a continuous‑control monitoring platform.
- Document remediation steps and retain logs as audit‑ready evidence of due diligence.
- Review and test incident‑response playbooks for ransomware containment on SharePoint‑derived footholds.
Source: The Record
Technical Notes
- Attack vector: exploitation of multiple SharePoint CVEs (including “ToolShell” and newer 2025/2026 bugs).
- Ransomware payload: Warlock, delivered after disabling endpoint security tools.
- Data types: operational documents, network credentials, and potentially sensitive government or utility data.
Source: Symantec Threat Hunter Team report