A suspected China-linked threat actor tracked as Warlock is chaining multiple Microsoft SharePoint vulnerabilities — both long-patched flaws and newer bugs — to gain a foothold on on-premises estates, then systematically disabling endpoint security tooling before deploying ransomware, according to analysis from the Symantec and Carbon Black Threat Hunter Team, as reported by The Hacker News on 3 October 2026.
The activity has so far been observed against organisations in Portuguese- and Spanish-speaking countries, with critical infrastructure, government and education environments among those affected. Those sectors should be read as context for the observed campaign footprint rather than a confirmed targeting list — and for administrators elsewhere running comparable Microsoft estates, the tradecraft matters more than the geography.
The sequence to watch
The operation follows a three-stage pattern that makes it unusually hard to catch. First comes initial access through SharePoint: the attackers chain older, well-known on-premises SharePoint flaws with more recent disclosures, which means an estate patched only to the latest bulletin can still be exposed if an older instance was never brought current or if a legacy server was never decommissioned.
Second — and this is where the campaign diverges from conventional ransomware intrusions — the attackers tamper with endpoint protection. The researchers describe security agents being neutralised, protected services manipulated and logs cleared, with the practical effect that the intrusion becomes quieter precisely as it escalates toward full compromise. Endpoint detection and response (EDR) telemetry that would ordinarily light up during lateral movement and privilege escalation is absent by the time the attackers are most active.
Only then is ransomware deployed, landing in an environment where the controls most likely to detect and stop it have already been turned off or degraded.
The sequencing is the point: EDR is not disabled at the moment of intrusion, but after initial access has been secured and immediately before the decisive phase. The layer defenders count on most is the one neutralised at the point it matters most — and by the time encryption runs, the telemetry that would have flagged the tampering is already gone.
What the attribution does and does not tell us
The "China-linked" label carries a consistent pattern of hedging in this space, and this campaign fits it. Warlock has been linked by security researchers to activity overlapping with groups long associated with China-based operations, but attribution in ransomware and espionage cases remains probabilistic, not forensic certainty.
More significant than the origin is the trend shift the activity illustrates. Historically espionage-focused clusters attributed to Chinese-speaking actors have increasingly blended destructive ransomware operations into their tradecraft. The line between intelligence gathering and financially motivated extortion is continuing to blur, which means defenders can no longer dismiss unusual intrusion behaviour as "just intelligence collection" — and equally, cannot assume an extortion attempt lacks a strategic dimension.
Defending the on-premises estate
For administrators in organisations running on-premises or hybrid Microsoft environments, the practical guidance from this campaign is straightforward:
- Treat internet-facing SharePoint as priority one. Patch verification should not stop at checking that the newest security bulletin has been applied. The operative question is whether every internet-facing instance is actually current, and whether unpatched legacy servers remain reachable.
- Assume exposure. If SharePoint has ever been exposed to the internet, plan remediation on the assumption that initial access has already occurred.
- Audit endpoint agent integrity, not just deployment. Centrally deployed security agents are worthless if nobody checks whether they are still running, still logging, and still enforcing policy. Tamper-protection features should be validated and monitored for unexpected service stops or configuration changes.
- Test recovery paths. Backups are only as good as the last verified restore — test them, and store copies out of band.
- Review service and unprivileged account privileges. Lateral movement and agent tampering both depend on accounts holding more rights than they need.
The uncomfortable lesson of the Warlock campaign is that many organisations invest heavily in endpoint detection while leaving the initial-access layer — an internet-facing SharePoint server — unattended. Both layers have to hold: a patch bulletin proves an update was applied, but only an integrity audit proves the defences are still standing watch over it.
據 Symantec 與 Carbon Black Threat Hunter Team 的分析指出,一個被追蹤為 Warlock、疑似與中國有關的威脅行為者,正在連環利用多個 Microsoft SharePoint 漏洞——包括早已修補的舊漏洞及較新披露的漏洞——以在企業內部網絡環境中取得立足點,其後有系統地停用端點安全工具,再投放勒索軟件。有關分析由 The Hacker News 於 2026 年 10 月 3 日報道。
迄今,相關活動已在使用葡萄牙語及西班牙語的國家的機構中被偵測到,受影響者包括關鍵基礎設施、政府及教育機構。上述行業應視為此次攻擊活動範圍的背景脈絡,而非已確認的攻擊目標清單——對於其他地方運行類似 Microsoft 環境的管理員而言,其作案手法遠比地域分佈更值得關注。
值得留意的攻擊次序
今次行動遵循三階段模式,因而極難察覺。第一步是透過 SharePoint 取得初始存取權:攻擊者將較早、已廣為人知的 SharePoint 內部網絡漏洞與較新披露的漏洞串連利用。這意味著即使整個環境已套用最新安全通告,只要較舊的安裝從未更新至最新版本,或已退役的舊伺服器從未移除,仍有被入侵的可能。
第二步——亦是今次行動與傳統勒索軟件入侵的分野所在——是攻擊者篡改端點防護。研究人員指出,安全代理程式被中和、受保護的服務遭操縱、日誌亦被清除,實際效果是:入侵在向全面入侵逐步升級的同時反而變得更為隱蔽。當入侵偵測與回應(EDR)遙測資料原本會在橫向移動及權限提升階段觸發警報之時,到了攻擊者活動最為頻繁的時刻,這些資料卻早已不復存在。
之後才會投放勒索軟件,而落點所在環境中,最有可能偵測及阻止攻擊的控制措施,卻早已被關閉或削弱。
這個先後次序正是重點所在:EDR 並非在入侵一刻就被停用,而是在初始存取權已穩固取得之後、緊接決定性階段之前才被關閉。防禦者最依賴的那一層防護,恰恰在最關鍵時刻被中和——而到加密作業啟動時,原本足以標示篡改行為的遙測資料早已消失。
歸因分析能與不能告訴我們的事
「與中國有關」這一標籤在這個領域向來伴隨大量保留措辭,今次行動亦不例外。安全研究人員已將 Warlock 與長久被認為與中國境內行動相關的組織有所重疊,但在勒索軟件及間諜活動案件中,歸因始終是概率性的推斷,而非法證層面的確定結論。
比源頭更值得關注的,是此活動所顯示的趨勢轉變。歷史上被歸因於使用中文的行為者的間諜活動群組,已越來越常將具破壞性的勒索軟件行動融入其作案手法之中。情報蒐集與以金錢為動機的勒索之間的界線持續模糊,這意味著防禦者不能再將異常的入侵行為視作「單純的情報蒐集」;同樣地,也不能假定勒索嘗試完全沒有戰略層面的考量。
保護企業內部網絡環境
對於在機構內運行 Microsoft 內部網絡或混合式環境的管理員而言,今次行動帶來的實用指引十分直接:
- 將對外互聯網的 SharePoint 視為第一優先。 修補程式的驗證不應止於確認最新安全通告已套用。關鍵問題是每一個對外的安裝是否真正已更新至最新版本,以及尚未修補的舊伺服器是否仍可被存取。
- 假設環境已遭暴露。 如果 SharePoint 曾經對外接通互聯網,就應假定初始入侵已經發生,並據此規劃補救措施。
- 審核端點代理程式的完整性,而不只是部署覆蓋率。 中央部署的安全代理程式若無人檢查其是否仍在運行、仍在記錄日誌及仍在執行政策,形同無用。防篡改功能應加以驗證,並監測是否出現意外的服務停止或配置變更。
- 測試復原路徑。 備份的價值只取決於最近一次經核實的還原是否成功——務必測試,並在異地保存副本。
- 檢視服務帳戶及非特權帳戶的權限。 橫向移動與代理程式篡改,兩者都依賴擁有超出實際需要權限的帳戶。
Warlock 行動帶來令人不安的一課:許多機構在端點偵測方面投入大量資源,卻對初始存取那一層——一部對外互聯網的 SharePoint 伺服器——疏於看顧。兩個層面缺一不可:修補通告只能證明更新已套用,唯有完整性審核,才能證明防線仍在持續守護。
