China-linked Warlock gang exploits SharePoint flaws to deploy ransomware against critical infrastructure

Warlock, a Chinese ransomware group, has launched attacks against water utilities, telecom providers, government agencies, and universities by exploiting known SharePoint vulnerabilities for initial access. The threat actor, also tracked as Longlegs by Symantec, has focused on Portuguese and Spanish-speaking regions over the past two months and deployed driver-based tools to disable security software before encrypting systems. In one incident, the group disabled endpoint protection on 40 systems within hours and deployed ransomware to at least 33 hosts.
Warlock's operational approach demonstrates a methodical attack chain designed to maximize damage across enterprise networks. The group exploited multiple SharePoint vulnerabilities to establish initial footholds, then used legitimate tools like Visual Studio Code and penetration testing frameworks to move laterally through networks. Their targeting of Portuguese and Spanish-speaking regions suggests either operational focus or language capability within the group.
The use of signed vulnerable drivers to disable security protections represents a sophisticated evasion technique that allows attackers to operate freely once endpoint defenses are compromised. By staging ransomware in SYSVOL shares and deploying via Group Policy, Warlock could potentially encrypt entire network segments simultaneously rather than targeting systems individually, significantly accelerating impact.
Critical infrastructure operators in water, telecommunications, and government sectors could face extended service disruptions if such attacks succeed, potentially affecting public safety and essential services. Organizations relying on on-premises SharePoint deployments may face heightened risk if vulnerabilities remain unpatched. The incident suggests that defenders operating in Portuguese and Spanish-speaking markets may require additional resources and threat intelligence sharing to identify and respond to similar campaigns before widespread encryption occurs.