Warlock Expands SharePoint Exploitation in Critical Infrastructure Attacks
Warlock ransomware operators continue exploiting unpatched SharePoint servers at critical infrastructure, government, and education targets.
Symantec says the Warlock ransomware group, linked to China-based Longlegs and Storm-2603, is still exploiting SharePoint at critical infrastructure, government, and education organizations. Over two months it hit at least four organizations in Portuguese- and Spanish-speaking countries, including a water utility, a telecommunications provider, a regional government body, and a university. In one intrusion, attackers disabled security software on at least 40 systems and ran Warlock on at least 33. The chain uses SharePoint bugs, including ToolShell and flaws such as CVE-2026-32201, then webshells, machine-key theft, DLL sideloading, a vulnerable driver, SYSVOL staging, and Visual Studio Code tunnels.
- Recent victims include a water utility, telecom, regional government, and a university.
- Security tools were disabled on 40 systems; Warlock encrypted at least 33.
- Intrusions use SharePoint exploits, webshells, and ASP.NET machine-key theft.
- Operators stage Warlock in SYSVOL and abuse Visual Studio Code tunnels.
- Cited flaws include CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164.
Vulnerabilities mentionedAll →
- CVE-2026-322016.543%Improper Input Validation Spoofing Vulnerability in Microsoft SharePoint Serverpublished · Microsoft SharePoint Server KEV
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | asp.net | rePoint flaws is typically followed by webshell deployment, ASP.NET machine key exfiltration, and the deployment of a forced si |
Full article477 words · extracted from securityweek.com · click to collapse
The Warlock ransomware group continues to target SharePoint servers in attacks against critical infrastructure, government, and education entities, Symantec reports.
Warlock is believed to be operated by a China-based hacking group tracked as Longlegs and Storm-2603, which has been linked to malicious operations such as CL-CRI-1040, CamoFei, and ChamelGang.
Last year, the Chinese state-sponsored groups Linen Typhoon and Violet Typhoon were seen exploiting two SharePoint vulnerabilities dubbed ToolShell as zero-days at least two weeks before public disclosure.
Within weeks, more than 400 SharePoint servers were compromised, and Storm-2603’s exploitation of ToolShell stood out amid heavy APT activity.
By October 2025, researchers uncovered numerous Warlock ransomware attacks that exploited ToolShell. Some of the group’s victims included a Middle East telecom firm, African and South American government entities, and a US university.
According to a fresh Symantec report, Storm-2603 continues to favor the exploitation of SharePoint bugs in attacks. In addition to ToolShell, its arsenal may also include recent flaws such as CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, CVE-2026-58644, CVE-2026-50522, and CVE-2026-55040.
Advertisement. Scroll to continue reading.
Over the past two months, the Warlock operator has hit at least four victim organizations in Portuguese- and Spanish-speaking countries.
“The victims included two critical infrastructure operators, a water utility and a telecommunications provider, along with a regional government body and a university,” Symantec reports.
As part of one intrusion, the hacking group deployed a tool to disable the security software on at least 40 systems and then executed Warlock on at least 33 of them.
The group’s exploitation of SharePoint flaws is typically followed by webshell deployment, ASP.NET machine key exfiltration, and the deployment of a forced signed payload for remote code execution (RCE).
Storm-2603 relies on DLL sideloading for in-memory code execution, drops additional payloads from legitimate file-sharing and storage services and a vulnerable driver to disable security tools, and relies on living-off-the-land tools for reconnaissance and command execution.
“The group has also been observed abusing Visual Studio Code’s built-in tunnel feature, installing the code-insiders.exe binary as a service to establish covert remote network access that blends into traffic that typically originates from developer or administrator workstations,” Symantec notes.
Additionally, the threat actor stages the Warlock payload inside the domain’s SYSVOL share, which is automatically replicated to every domain controller and is readable domain-wide, to execute the file-encrypting ransomware at scale.
“Longlegs’ continued activity, more than a year after Warlock ransomware first came to prominence, shows that exploitation of ToolShell and other related SharePoint vulnerabilities remains a viable initial access route for attackers on SharePoint deployments that have not been patched or otherwise mitigated,” Symantec notes.
Related: Russian APT Star Blizzard Uses ‘RedFlick’ Infection Chain in Recent Attacks
Related: Hackers Use ChatGPT Custom GPTs in ClickFix Attacks
Related: Daemon Tools Hackers’ NeedyMantis Malware Dissected by Microsoft
Related: SmarterTools Hit by Ransomware via Vulnerability in Its Own Product