Warlock Hackers Are Quietly Killing Security Tools Before Ransomware Strikes

·
Listen to this article~4 min
Warlock Hackers Are Quietly Killing Security Tools Before Ransomware Strikes

Warlock, a suspected China-linked threat actor, is exploiting SharePoint flaws to disable security tools before deploying ransomware. Here's what's happening and how to protect your organization.

Imagine this: you show up to work, coffee in hand, and every screen in the building is locked. Your security software? Silent. Disabled. Gone. That's not a hypothetical — that's the exact playbook a threat group called Warlock is running right now, and it's worth paying attention to even if you don't live in a Portuguese- or Spanish-speaking country. ### Who Is Warlock, and Why Should You Care? Warlock is a suspected China-linked threat actor. Researchers from the Symantec and Carbon Black Threat Hunter Team have been tracking its activity closely, and what they're seeing isn't random noise. It's a coordinated campaign. The targets? Critical infrastructure, government agencies, and educational institutions. Not exactly small fish. Here's the uncomfortable part: the attackers are exploiting Microsoft SharePoint vulnerabilities — likely a mix of old, unpatched flaws and newer ones. And SharePoint isn't some obscure tool nobody uses. It's everywhere. If your organization runs it, you're on the radar. ### How the Attack Actually Unfolds The sequence matters here, because it tells you what to look for: - First, Warlock finds a way in through a SharePoint vulnerability. - Then, before doing anything loud, it disables security tools — antivirus, endpoint detection, whatever's standing in the way. - Only after the defenses are down does the ransomware get deployed. That order is deliberate. It buys the attackers time and reduces the chance anyone notices until it's too late. As one security researcher put it, "The scariest part isn't the ransomware itself — it's how quietly everything gets switched off before it hits." ### Why Old Vulnerabilities Still Work This is the part that frustrates defenders the most. Attackers don't need zero-days to succeed. They just need targets that haven't patched yet. A vulnerability from two years ago, still unpatched on a server nobody's touched, is basically an open door. Warlock knows this. That's why it keeps recycling the same tricks. ### What You Can Actually Do About It You don't need a massive security budget to reduce your risk. You need consistency. - Patch SharePoint promptly — don't wait for the next maintenance window. - Monitor for unexpected changes to your security tool configurations. - Segment your network so a single compromised system doesn't open everything. - Train your team to spot unusual behavior, not just obvious phishing. ### The Bigger Picture Ransomware groups are getting smarter about the setup phase. They're not just smashing windows anymore — they're picking locks, turning off alarms, and walking out the front door. Warlock is a reminder that the quiet moments before an attack are where the real damage gets prepared. If your security tools can be disabled remotely, you need to know how — and you need to close that gap before someone else finds it first.