Warlock Expands SharePoint Exploitation in Critical Infrastructure Attacks
Warlock ransomware intensifies SharePoint exploitation in targeted cyberattacks, according to Symantec.
Warlock Ransomware Intensifies SharePoint Exploitation in Targeted Cyberattacks
The Warlock ransomware operation has intensified its focus on exploiting SharePoint servers in attacks targeting critical infrastructure, government, and educational institutions, as noted by Symantec. The group, attributed to a China-based hacking collective known as Longlegs and Storm-2603, has been associated with prior campaigns such as CL-CRI-1040, CamoFei, and ChamelGang. Recent analysis reveals that within weeks of increased activity, over 400 SharePoint servers were compromised, with Storm-2603’s use of the ToolShell exploit standing out amid broader advanced persistent threat (APT) operations.
By October 2025, researchers identified multiple Warlock ransomware incidents leveraging ToolShell. Affected entities included a Middle Eastern telecommunications company, government agencies in Africa and South America, and a U.S. university. A new Symantec report highlights that Storm-2603 continues to prioritize SharePoint vulnerabilities in its attack campaigns. The group’s toolset includes recent flaws such as CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, CVE-2026-58644, CVE-2026-50522, and CVE-2026-55040.
Over the past two months, Warlock has targeted at least four organizations in Portuguese- and Spanish-speaking regions. These victims encompassed two critical infrastructure providers, a water utility, a telecommunications firm, a regional government entity, and a university. During one intrusion, the threat actor disabled security software on 40 systems and deployed Warlock on 33 of them.
Exploitation of SharePoint Vulnerabilities
The exploitation of SharePoint vulnerabilities typically involves webshell deployment, extraction of ASP.NET machine keys, and execution of a signed payload for remote code execution (RCE). Storm-2603 employs DLL sideloading for in-memory code execution, deploys additional payloads via legitimate file-sharing platforms, and uses a vulnerable driver to neutralize security tools.
The group also utilizes living-off-the-land tools for reconnaissance and command execution. Notably, it has been observed leveraging the built-in tunnel feature of Visual Studio Code, installing the code-insiders.exe binary as a service to establish covert remote access that mimics traffic from developer or administrator workstations.
Ransomware Deployment Mechanisms
The ransomware payload is staged within the domain’s SYSVOL share, which is replicated across all domain controllers and accessible domain-wide, enabling large-scale deployment of the file-encrypting ransomware. Symantec emphasizes that Longlegs’ ongoing activities, more than a year after Warlock’s initial emergence, underscore the continued viability of exploiting unpatched SharePoint vulnerabilities as an initial access vector.
Technical Tactics and Attack Methodology
The group’s attack chain begins with the exploitation of unpatched SharePoint flaws, followed by the deployment of webshells to maintain persistence. These webshells facilitate the exfiltration of ASP.NET machine keys, which are critical for decrypting session data and bypassing authentication mechanisms.
The subsequent deployment of a signed payload enables remote code execution, allowing the threat actor to execute arbitrary commands on compromised systems. To evade detection, Storm-2603 employs DLL sideloading, a technique that loads malicious code into the address space of a legitimate process. This method avoids direct execution of malicious files, reducing the likelihood of detection by traditional antivirus solutions.
Additionally, the group leverages legitimate file-sharing and storage services to drop secondary payloads, further obfuscating its activities. A key component of the attack involves the use of a vulnerable driver to disable endpoint protection tools, creating a window for undetected ransomware deployment.
The group also relies on living-off-the-land tools, such as PowerShell and Windows Management Instrumentation (WMI), to conduct reconnaissance and execute commands without introducing external malware. The integration of Visual Studio Code’s tunnel feature represents a novel approach to establishing persistent access.
Scale and Impact of Recent Campaigns
The recent Warlock campaigns have demonstrated a strategic focus on organizations in Portuguese- and Spanish-speaking countries, with attacks targeting critical infrastructure sectors. The compromise of a water utility and telecommunications provider underscores the group’s interest in disrupting essential services.
The inclusion of a regional government body and a university further indicates a broad targeting strategy aimed at both public and academic institutions. The scale of these operations is evident in the deployment of Warlock on 33 systems following the disabling of security software on 40 devices.
This suggests a coordinated effort to maximize the impact of the ransomware, potentially leading to significant operational downtime and financial losses. The use of the SYSVOL share for payload delivery highlights the group’s ability to execute attacks at an organizational level, leveraging the inherent replication mechanisms of Active Directory.
Ongoing Threat and Mitigation Recommendations
Symantec’s analysis emphasizes the urgency of patching SharePoint vulnerabilities and implementing robust mitigation strategies. The continued exploitation of ToolShell and related flaws demonstrates that unpatched systems remain a prime target for threat actors.
Organizations are advised to monitor for signs of webshell activity, review ASP.NET configuration settings, and ensure that all software is up to date with the latest security patches. The use of legitimate tools and services by Storm-2603 underscores the need for behavioral analysis and anomaly detection.
According to Symantec, Longlegs’ ongoing activities, more than a year after Warlock’s initial emergence, underscore the continued viability of exploiting unpatched SharePoint vulnerabilities as an initial access vector.
Security teams should focus on identifying unusual patterns in network traffic, such as unexpected use of Visual Studio Code tunnels or unauthorized access to SYSVOL shares. Additionally, implementing strict access controls and regularly auditing privileged accounts can help mitigate the risk of lateral movement within a network.
As the threat landscape evolves, the persistence of groups like Longlegs and Storm-2603 highlights the importance of proactive defense measures. Organizations must remain vigilant against emerging attack vectors and adapt their security strategies to address the growing sophistication of ransomware campaigns.
