MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-10-02 · via BleepingComputer

China-linked Warlock gang exploits SharePoint flaws to deploy ransomware against critical infrastructure

Image via BleepingComputer
Image via BleepingComputer

Warlock, a Chinese ransomware group, has launched attacks against water utilities, telecom providers, government agencies, and universities by exploiting known SharePoint vulnerabilities for initial access. The threat actor, also tracked as Longlegs by Symantec, has focused on Portuguese and Spanish-speaking regions over the past two months and deployed driver-based tools to disable security software before encrypting systems. In one incident, the group disabled endpoint protection on 40 systems within hours and deployed ransomware to at least 33 hosts.

Expanded Detail

Warlock's operational approach demonstrates a methodical attack chain designed to maximize damage across enterprise networks. The group exploited multiple SharePoint vulnerabilities to establish initial footholds, then used legitimate tools like Visual Studio Code and penetration testing frameworks to move laterally through networks. Their targeting of Portuguese and Spanish-speaking regions suggests either operational focus or language capability within the group.

The use of signed vulnerable drivers to disable security protections represents a sophisticated evasion technique that allows attackers to operate freely once endpoint defenses are compromised. By staging ransomware in SYSVOL shares and deploying via Group Policy, Warlock could potentially encrypt entire network segments simultaneously rather than targeting systems individually, significantly accelerating impact.

Context

Critical infrastructure operators in water, telecommunications, and government sectors could face extended service disruptions if such attacks succeed, potentially affecting public safety and essential services. Organizations relying on on-premises SharePoint deployments may face heightened risk if vulnerabilities remain unpatched. The incident suggests that defenders operating in Portuguese and Spanish-speaking markets may require additional resources and threat intelligence sharing to identify and respond to similar campaigns before widespread encryption occurs.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at BleepingComputer →
Related stories
Critical Infrastructure Vulnerabilities and IoT Threats Dominate October Security Landscape · Cybersecurity
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “Warlock ransomware breach SharePoint in water, telecom operator attacks.” Browse more stories.