Warlock ransomware group targets SharePoint flaws in critical infrastructure
The Warlock threat actor continues exploiting Microsoft SharePoint vulnerabilities to deploy ransomware against organizations in Portuguese- and Spanish-speaking regions.
The suspected China-linked threat actor known as Warlock is actively exploiting Microsoft SharePoint vulnerabilities to target organizations in Portuguese- and Spanish-speaking countries. Observed by the Symantec and Carbon Black Threat Hunter Team, these attacks have impacted critical infrastructure, government bodies, and educational institutions across Europe, Africa, and Latin America.
What happened
In the past two months, the group, also tracked as Longlegs, Gold Salem, and Storm-2603, has attacked at least four organizations. The victims include two critical infrastructure operators, specifically a water utility and a telecommunications provider, along with a regional government body and a university. This activity marks a continuation of campaigns that gained prominence in mid-2025 through the exploitation of "ToolShell" SharePoint flaws.
The attackers have demonstrated a high degree of operational speed and scale. In one intrusion against a critical infrastructure operator, the threat actors deployed a tool designed to disable security software on at least 40 hosts within approximately two hours. Following this disarmament phase, they deployed the Warlock ransomware binary on at least 33 hosts. They achieved this widespread deployment by staging the payload in the domain's SYSVOL share, leveraging ordinary domain replication to distribute the malware automatically across the network.
Warlock shares technical overlaps with older activity clusters such as CL-CRI-1040, CamoFei, and ChamelGang. Earlier in the year, the group was also linked to the compromise of SmarterTools by exploiting an unpatched SmarterMail instance. The recent focus on specific linguistic regions suggests either opportunistic targeting of exposed servers or a more deliberate strategic tasking, though the exact motivation remains unclear.
How it works
The attack chain begins with the exploitation of multiple vulnerabilities in on-premises Microsoft SharePoint Server deployments. Once initial access is gained, the threat actors drop web shells capable of targeting various SharePoint versions. The primary objective of these web shells is to harvest the SharePoint farm's ASP.NET machine keys. With these keys, the attackers forge validly signed payloads, allowing them to achieve remote code execution directly inside the SharePoint application pool.
To maintain persistence and evade detection, Warlock employs several sophisticated techniques. They use DLL sideloading to inject malicious code into memory and download follow-on payloads from legitimate cloud storage services like catbox[.]moe and wasabisys[.]com. A notable tactic involves the "bring your own vulnerable driver" (BYOVD) method, where they abuse the legitimate but vulnerable K7RKScan.sys driver (CVE-2025-1055) to disable security software. This same driver was previously exploited by DragonForce ransomware actors.
The group also relies heavily on living-off-the-land (LotL) tools for reconnaissance and command execution. This includes abusing the built-in tunnel feature of Microsoft Visual Studio Code to establish remote connections to infected systems. For command-and-control operations, they have utilized legitimate tools such as Velociraptor. As recently as July 22, 2026, these methods were used to drop web shells, conduct discovery, execute code, burrow deeper into networks, and ultimately deploy ransomware.
Key details
- Warlock, also known as Longlegs, Gold Salem, and Storm-2603, targets Portuguese- and Spanish-speaking organizations.
- Recent victims include critical infrastructure operators, government bodies, and universities in Europe, Africa, and Latin America.
- Attackers exploit SharePoint vulnerabilities to steal ASP.NET machine keys and forge signed payloads for remote code execution.
- The group uses the BYOVD technique with driver K7RKScan.sys (CVE-2025-1055) to disable security software on compromised hosts.
- Ransomware is distributed at scale by staging payloads in the domain's SYSVOL share for automatic replication.
- Living-off-the-land tactics include abusing Visual Studio Code tunnels and using Velociraptor for command-and-control.
Why it matters
For software engineers and IT leads managing on-premises infrastructure, this campaign highlights the persistent risk associated with unpatched SharePoint servers. The ability of attackers to forge signed payloads using stolen machine keys bypasses many traditional integrity checks, making detection difficult until the ransomware is already deployed. The use of legitimate tools like VS Code and Velociraptor further blurs the line between administrative activity and malicious behavior, complicating incident response efforts.
The speed at which Warlock disables security tools and propagates ransomware via SYSVOL demonstrates the importance of robust network segmentation and rapid patch management. Organizations relying on legacy or unmitigated SharePoint deployments remain viable targets more than a year after the initial ToolShell exploits emerged. This underscores the need for continuous vulnerability assessment and the hardening of internal replication mechanisms to prevent lateral movement.
What you can do
- Immediately patch all on-premises Microsoft SharePoint Server installations to address known vulnerabilities including ToolShell flaws.
- Monitor for unusual use of legitimate tools such as Visual Studio Code tunnels and Velociraptor on production servers.
- Restrict write access to the SYSVOL share to prevent unauthorized staging of payloads for domain-wide replication.
- Audit and update vulnerable drivers like K7RKScan.sys to mitigate BYOVD attacks that disable security software.
- Implement strict controls over ASP.NET machine key access and monitor for attempts to export or misuse these keys.
- Review network logs for connections to known file-sharing services like catbox[.]moe and wasabisys[.]com used for payload delivery.



