← Back to briefings

'Warlock' Ransomware Group Targets Critical Infrastructure in Portuguese and Spanish-Speaking Countries

Cybersecurity2026-10-02·4 min read

Symantec researchers found that the Warlock ransomware campaign has continued into 2026, targeting critical infrastructure in Portuguese and Spanish-speaking countries.

The attackers are exploiting unpatched SharePoint vulnerabilities, including both 2025 and 2026 vulnerabilities, to gain access to victim networks.

The apparent focus on Portuguese- and Spanish-speaking countries suggests either opportunistic targeting of exposed servers or a deliberate tasking by the threat actors.

The inclusion of critical infrastructure operators among victims highlights the potential real-world consequences of successful ransomware attacks against essential services.

In one incident, attackers used a tool to disable security software on dozens of hosts before deploying the Warlock ransomware.

The group conducted extensive reconnaissance on compromised systems, installing tools to blend their activities with normal network traffic.

This targeting pattern demonstrates how ransomware groups adapt their tactics to exploit specific vulnerabilities and target particular geographic or linguistic regions.

Organizations are urged to patch SharePoint vulnerabilities promptly and implement robust backup and incident response procedures.

Source: The Record from Recorded Future News. This article summarizes the linked reporting and distinguishes announced plans from demonstrated results.