Connect with us

Security

Malevolent Warlock Harnesses SharePoint Vulnerabilities to Disable Security Measures and Unleash Ransomware

Published

on

The Persistent Threat of Warlock: Exploiting Microsoft SharePoint Vulnerabilities

A threat actor believed to be linked to China, known as Warlock, continues to exploit vulnerabilities in Microsoft SharePoint, targeting organizations in Portuguese- and Spanish-speaking countries. This ongoing activity has been observed by the Symantec and Carbon Black Threat Hunter Team, with critical infrastructure, government, and education institutions falling victim.

Over the past two months, Warlock, also known as Gold Salem, Longlegs, and Storm-2603, has targeted at least four organizations, including a water utility, a telecommunications provider, a regional government body, and a university. These attacks have impacted organizations across Europe, Africa, and Latin America.

Warlock gained notoriety in mid-2025 for exploiting zero-day vulnerabilities in SharePoint, specifically the “ToolShell” flaws, to deploy ransomware on targeted systems. More recently, the group was linked to the compromise of SmarterTools by exploiting an unpatched SmarterMail instance. They have also utilized legitimate tools like Velociraptor for command-and-control and the BYOVD technique to bypass security software on compromised hosts.

According to Symantec, Warlock’s activities align with older threat clusters such as CL-CRI-1040, CamoFei, and ChamelGang. In one critical infrastructure attack, the threat actors deployed a tool to disable security software on multiple hosts before deploying Warlock on a significant number of machines.

Warlock’s attacks have exploited various vulnerabilities in Microsoft SharePoint Server deployments, dropping web shells that target multiple versions of SharePoint. These web shells aim to collect ASP.NET machine keys from the SharePoint farm to forge validly signed payloads and achieve remote code execution.

Additional tactics employed by Warlock include DLL sideloading, downloading payloads from cloud services to evade detection, exploiting vulnerable drivers like K7RKScan.sys, using LotL tooling for reconnaissance, staging payloads in SYSVOL shares, and exploiting VS Code features for remote connections.

See also  Riot's Vanguard Anti-Cheat: The New On-Demand Security Feature

As of July 22, 2026, Warlock has continued to exploit SharePoint vulnerabilities to conduct discovery, obtain code execution, deploy additional payloads, establish tunnels, disable security software, and deploy ransomware. This persistence highlights the ongoing threat posed by unpatched SharePoint deployments.

The recent focus on Portuguese- and Spanish-speaking countries suggests either opportunistic targeting of vulnerable servers or a deliberate strategy by the threat actors. Organizations are urged to patch and secure their SharePoint deployments to mitigate the risk of falling victim to Warlock’s attacks.

Trending