The suspected China-linked threat actor known as Warlock is actively continuing to weaponize Microsoft SharePoint vulnerabilities, leveraging both older and recently disclosed flaws in a sustained campaign directed at organizations across Portuguese- and Spanish-speaking countries. According to recent findings published by the Symantec and Carbon Black Threat Hunter Team, a unit owned by Broadcom, the ongoing malicious activity has successfully struck high-value targets, including critical infrastructure operators, regional government bodies, and educational institutions. The targeting pattern highlights a persistent and evolving threat vector centered around on-premises Microsoft SharePoint Server deployments that remain unpatched or inadequately secured against sophisticated intrusion methods. Read Also: Mastering Identity Visibility: The Critical Starting Point for Modern Cloud and Multicloud Security Critical Security Flaw Discovered in Elementor Plugin Threatens Over Two Million WordPress Sites Over the past two months alone, security researchers have tracked the threat group—also known by alternative monikers such as Gold Salem, Longlegs, and Storm-2603—as it targeted at least four distinct organizations. Among the affected entities are two critical infrastructure operators comprising a water utility and a telecommunications provider, alongside a regional government body and a university. Geographically, these victims span across Europe, Africa, and Latin America, united primarily by their linguistic footprint in Portuguese- and Spanish-speaking regions. The threat group first gained widespread prominence in mid-2025 in connection with the zero-day exploitation of the "ToolShell" SharePoint vulnerabilities. During that initial wave of high-profile activity, the threat actors utilized these flaws to establish unauthorized access and rapidly deploy ransomware payloads across compromised systems. Since then, the collective has continued to refine its operational toolset, demonstrating an ability to pivot across various enterprise software vulnerabilities and adopt advanced evasion techniques. Earlier this year, the actor was linked to the compromise of SmarterTools infrastructure by exploiting an unpatched instance of SmarterMail. Furthermore, the group has increasingly relied on legitimate administrative and dual-use tools to facilitate its operations. Investigators have observed Warlock utilizing tools like Velociraptor for command-and-control communication, as well as employing the "bring your own vulnerable driver" technique to systematically disarm security software running on a compromised host before executing destructive payloads. Threat intelligence analysis conducted by Symantec indicates that Warlock shares significant tactical, operational, and infrastructural overlaps with older, well-documented activity clusters. These include clusters previously tracked under identifiers such as CL-CRI-1040, CamoFei, and ChamelGang, suggesting a lineage of sophisticated cyber espionage or financially motivated campaigns originating from the same broader threat nexus. The mechanics of Warlock’s intrusion methodology are both rapid and methodical. In a documented intrusion against a critical infrastructure operator, the attackers successfully pushed a specialized tool designed to disable security software to at least 40 hosts within a compressed timeframe of approximately two hours. Following the neutralization of endpoint defenses, the threat actors deployed the Warlock ransomware on at least 33 of those hosts. To streamline the deployment process, the actors staged the ransomware binary within the domain’s SYSVOL share, allowing ordinary domain replication mechanisms to deliver the malicious payload to target machines automatically. The primary entry point for these attacks consistently leverages vulnerabilities found in on-premises Microsoft SharePoint Server deployments. Upon securing initial access, the threat actors deploy customized web shells capable of targeting multiple versions of SharePoint. The fundamental objective of these web shells is to quietly harvest the SharePoint farm’s ASP.NET machine keys. Once acquired, these cryptographic keys are abused to forge validly signed payloads, enabling the attackers to achieve remote code execution directly inside the SharePoint application pool without raising immediate alarms. Investigative timelines compiled by cybersecurity researchers show that these operational patterns have remained consistent throughout the year. As recently as late July, the threat actors were observed exploiting SharePoint Server flaws to drop persistent web shells, conduct internal network discovery, and secure arbitrary code execution inside the SharePoint application pool. From there, the intruders deployed secondary payloads to burrow deeper into the corporate network, established Visual Studio Code tunnels to maintain persistent access, systematically terminated active security software, and ultimately initiated the deployment of the ransomware binary. The persistence demonstrated by Longlegs, more than a year after the Warlock ransomware first emerged as a major concern, underscores the enduring risk posed by unpatched enterprise software. The continued exploitation of ToolShell and related SharePoint vulnerabilities demonstrates that these attack surfaces remain a viable initial access route for motivated threat actors targeting organizations that have failed to apply necessary patches or implement robust compensatory mitigations. Regarding the geographic and linguistic focus of the recent campaign, security analysts suggest two primary hypotheses. The targeting of Portuguese- and Spanish-speaking countries may reflect an opportunistic pattern driven entirely by the automated discovery of exposed and vulnerable SharePoint servers globally. Alternatively, it could represent a more deliberate, targeted tasking aligned with specific strategic or financial objectives set by the operators. As organizations continue to navigate an evolving threat landscape, the activity of the Warlock group serves as a stark reminder of the critical importance of timely vulnerability management, rigorous patch deployment, and continuous monitoring of enterprise collaboration platforms. Post navigation MI5 Warns Over 100 U.K. Academics Inadvertently Assisted Chinese State Security Intelligence Operations