China-Linked Threat Actor Warlock Exploits SharePoint Vulnerabilities to Deploy Ransomware and Bypass Security
A China-linked threat group, Warlock, is exploiting Microsoft SharePoint vulnerabilities to disable security tools and deploy ransomware against critical infrastructure and government entities in Portuguese- and Spanish-speaking regions. The attacks involve techniques like BYOVD, web shells, and exploiting unpatched flaws to achieve remote code execution and ransomware deployment.
The suspected China-linked threat actor known as Warlock is still continuing to weaponize Microsoft SharePoint vulnerabilities, likely both old and new, in attacks targeting organizations in Portuguese- and Spanish-speaking countries.
The activity, observed by the Symantec and Carbon Black Threat Hunter Team, has hit critical infrastructure, government, and education organizations.
"In the
*** END OF TRANSMISSION ***