Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Malware & Threats

Warlock Expands SharePoint Exploitation in Critical Infrastructure Attacks

The China-based hacking group has been exploiting SharePoint vulnerabilities since July 2025.

SharePoint vulnerability exploited

The Warlock ransomware group continues to target SharePoint servers in attacks against critical infrastructure, government, and education entities, Symantec reports.

Warlock is believed to be operated by a China-based hacking group tracked as Longlegs and Storm-2603, which has been linked to malicious operations such as CL-CRI-1040, CamoFei, and ChamelGang.

Last year, the Chinese state-sponsored groups Linen Typhoon and Violet Typhoon were seen exploiting two SharePoint vulnerabilities dubbed ToolShell as zero-days at least two weeks before public disclosure.

Within weeks, more than 400 SharePoint servers were compromised, and Storm-2603’s exploitation of ToolShell stood out amid heavy APT activity.

By October 2025, researchers uncovered numerous Warlock ransomware attacks that exploited ToolShell. Some of the group’s victims included a Middle East telecom firm, African and South American government entities, and a US university.

According to a fresh Symantec report, Storm-2603 continues to favor the exploitation of SharePoint bugs in attacks. In addition to ToolShell, its arsenal may also include recent flaws such as CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, CVE-2026-58644, CVE-2026-50522, and CVE-2026-55040.

Advertisement. Scroll to continue reading.

Over the past two months, the Warlock operator has hit at least four victim organizations in Portuguese- and Spanish-speaking countries.

“The victims included two critical infrastructure operators, a water utility and a telecommunications provider, along with a regional government body and a university,” Symantec reports.

As part of one intrusion, the hacking group deployed a tool to disable the security software on at least 40 systems and then executed Warlock on at least 33 of them.

The group’s exploitation of SharePoint flaws is typically followed by webshell deployment, ASP.NET machine key exfiltration, and the deployment of a forced signed payload for remote code execution (RCE).

Storm-2603 relies on DLL sideloading for in-memory code execution, drops additional payloads from legitimate file-sharing and storage services and a vulnerable driver to disable security tools, and relies on living-off-the-land tools for reconnaissance and command execution.

“The group has also been observed abusing Visual Studio Code’s built-in tunnel feature, installing the code-insiders.exe binary as a service to establish covert remote network access that blends into traffic that typically originates from developer or administrator workstations,” Symantec notes.

Additionally, the threat actor stages the Warlock payload inside the domain’s SYSVOL share, which is automatically replicated to every domain controller and is readable domain-wide, to execute the file-encrypting ransomware at scale.

“Longlegs’ continued activity, more than a year after Warlock ransomware first came to prominence, shows that exploitation of ToolShell and other related SharePoint vulnerabilities remains a viable initial access route for attackers on SharePoint deployments that have not been patched or otherwise mitigated,” Symantec notes.

Related: Russian APT Star Blizzard Uses ‘RedFlick’ Infection Chain in Recent Attacks

Related: Hackers Use ChatGPT Custom GPTs in ClickFix Attacks

Related: Daemon Tools Hackers’ NeedyMantis Malware Dissected by Microsoft

Related: SmarterTools Hit by Ransomware via Vulnerability in Its Own Product

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Learn how to address potential risks and not restrict AI adoption in your organization. See what a centralized AI gateway is and how it works in practice.

Register

Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction.

Register

People on the Move

Lumen Technologies has named Kim Keever as CSO.

Quantum Secure Encryption Corp. has appointed Joseph Hall as CIO.

David Cass has joined Grayscale Investments as Chief Risk Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.