Warlock Hackers Are Quietly Disabling Defenses Before Ransomware Hits

·
Listen to this article~4 min
Warlock Hackers Are Quietly Disabling Defenses Before Ransomware Hits

Warlock, a suspected China-linked group, is using SharePoint flaws to disable security tools and deploy ransomware. Here's what's happening and how to protect your organization.

Security teams have a new headache, and it's coming through a door most companies already have open. A threat actor called Warlock is using Microsoft SharePoint to slip past defenses, turn off security tools, and then drop ransomware. If your organization runs SharePoint, this one deserves your attention. ### What's Actually Happening Warlock is a suspected China-linked group. According to research from the Symantec and Carbon Black Threat Hunter Team, it's been weaponizing SharePoint vulnerabilities, both old and new, to break into networks. The targets so far? Critical infrastructure, government agencies, and educational institutions, mostly in Portuguese- and Spanish-speaking countries. But here's the thing: attackers don't stay in one region for long. The techniques they're using can easily travel. ### Why SharePoint Is the Weak Spot SharePoint is everywhere in corporate environments. It's how teams share documents, manage projects, and collaborate. That convenience is exactly what makes it a target. - It often sits on the network with broad access to internal systems - Many organizations lag on patching, leaving known flaws open for months - It's trusted by default, so security tools don't always flag unusual activity Warlock isn't just exploiting one bug. It's mixing old and new vulnerabilities, which means even companies that patched some issues might still be exposed. ### The Playbook: Disable, Then Destroy The scariest part of this campaign isn't the initial breach. It's what happens next. Warlock's operators focus on turning off endpoint protection and other security tools before deploying ransomware. Think of it like a burglar who cuts the alarm wires before walking through the front door. > "The most dangerous attacker isn't the one who breaks in. It's the one who makes you think nothing's wrong." That's exactly what's happening here. By the time ransomware shows up, the defenses that should have caught it are already offline. ### Who's at Risk If you're running SharePoint, you're potentially in the crosshairs. But some organizations are more exposed than others: - Government agencies with legacy systems - Schools and universities with limited IT budgets - Critical infrastructure operators where downtime isn't an option - Any company that's behind on patching The geographic focus on Portuguese- and Spanish-speaking regions doesn't mean US organizations are safe. Attackers follow opportunity, not borders. ### What You Can Do Right Now You don't need a massive security overhaul to reduce your risk. Start with the basics: - Patch SharePoint immediately. Don't wait for the next maintenance window. - Segment your network so a SharePoint breach doesn't give attackers the keys to everything. - Monitor for signs of security tools being disabled. That's a red flag. - Back up critical data offline. Ransomware can't encrypt what it can't reach. - Train your team to spot phishing, since that's often the entry point. ### The Bigger Picture Warlock is a reminder that attackers are patient. They don't rush in. They disable, they wait, and then they strike. The organizations that survive these campaigns aren't the ones with the biggest budgets. They're the ones that patch fast, monitor closely, and assume they're a target. SharePoint isn't going anywhere. Neither are the attackers who want to use it against you. The question is whether you'll close the door before they walk through it.