Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware
Warlock is exploiting SharePoint flaws to disable defenses and deploy ransomware against critical infrastructure and government targets.
Symantec and Carbon Black report that the suspected China-linked actor Warlock, also tracked as Storm-2603, Longlegs, and Gold Salem, continues to exploit on-premises Microsoft SharePoint flaws, including ToolShell, against Portuguese- and Spanish-speaking targets. In two months the group hit at least four organizations: a water utility, a telecommunications provider, a regional government body, and a university, across Europe, Africa, and Latin America. Intruders dropped web shells, collected ASP.NET machine keys to forge signed payloads, sideloaded DLLs, abused cloud storage, and used vulnerable driver K7RKScan.sys (CVE-2025-1055) to disable security tools. In one case they pushed a security-disabling tool to about 40 hosts and staged Warlock ransomware in SYSVOL so domain replication delivered it to at least 33 machines.