← Back to Feed

'Warlock' ransomware used in attacks on critical infrastructure in Portuguese, Spanish-speaking countries

October 2, 2026 · The Record · Severity: CRITICAL

The article details a new report from Symantec Threat Hunter Team about 'Warlock' ransomware, a group exploiting Microsoft SharePoint vulnerabilities to attack critical infrastructure in Portuguese and Spanish-speaking countries. The report emphasizes the importance of patching and monitoring for post-exploitation activity. 📌 **Analyst Note:** This serves as a reminder that ransomware groups increasingly target unpatched edge applications that sit close to sensitive data, so asset inventory and patch cadence for SharePoint should be treated as critical controls. Watch for exploit chaining if Microsoft releases an emergency fix, and ensure

Key Takeaways

  • The 'Warlock' ransomware group is actively targeting critical infrastructure in Portuguese and Spanish-speaking countries by exploiting known Microsoft SharePoint vulnerabilities, underscoring the risk of delayed patch management in mission-critical environments. Organizations using SharePoint should prioritize applying the relevant security updates immediately.
  • Symantec's threat intelligence reveals that the group employs a hands-on-keyboard approach, which means defenders should monitor for post-exploitation behaviors such as credential dumping, lateral movement, and scheduled task creation rather than relying on signature-based detection alone.
  • Critical infrastructure operators in Latin America and Iberian regions should harden their internet-facing collaboration platforms and implement network segmentation to limit the blast radius if an initial compromise occurs. Threat hunting should focus on unusual SharePoint service account activity and abnormal file encryption patterns.
☕ Buy a Coffee