China-linked Warlock group expands SharePoint exploitation in critical infrastructure attacks
The China-based threat actor Warlock has been actively exploiting SharePoint vulnerabilities since July 2025, with recent expansion into critical infrastructure sectors. The scope of affected organizations and specific sectors remain unclear, but the campaign signals sustained, targeted cyber espionage against high-value targets.
Score Breakdown
Intelligence Tags
Entities
Part of 2 situations
China — 122 developments
China-linked Warlock Group Exploits SharePoint in Critical Infrastructure Attacks
The China-linked Warlock ransomware group is actively exploiting SharePoint vulnerabilities for initial access, confirmed in attacks against a water utility, telecom provider, regional government body, and university. This campaign, ongoing since July 2025, indicates a sustained and expanding cyber espionage effort targeting critical infrastructure and public sector entities. The full scope of affected organizations and data impact remains unclear.