Ethical Hacking News
Warlock, a suspected China-linked threat actor, has been continuing to weaponize Microsoft SharePoint vulnerabilities in attacks targeting organizations in Portuguese- and Spanish-speaking countries. The activity has hit critical infrastructure, government, and education organizations, highlighting the severity of the threat posed by Warlock. The article delves into the tactics and techniques used by Warlock and the potential impact on organizations.
Warlock, a suspected China-linked threat actor, has been weaponizing Microsoft SharePoint vulnerabilities in attacks targeting organizations in Portuguese- and Spanish-speaking countries. Warlock has been exploiting vulnerabilities, likely both old and new, to disable security tools and deploy ransomware on targeted systems. Warlock has attacked at least four organizations, including critical infrastructure operators, a regional government body, and a university, in the past two months. Warlock gained prominence in mid-2025 by exploiting a zero-day vulnerability in SharePoint, known as "ToolShell", to deploy ransomware on targeted systems. Warlock shares overlaps with older activity clusters and has used legitimate tools like Velociraptor for command-and-control and the BYOVD technique to disarm security software. Warlock has leveraged multiple vulnerabilities in on-premises Microsoft SharePoint Server deployments to mount attacks. Warlock's tactics include using DLL sideloading, downloading payloads from legitimate cloud services, abusing vulnerable drivers, and using living-off-the-land tooling. The continued activity of Warlock shows that exploitation of ToolShell and other related-SharePoint vulnerabilities remains a viable initial access route for attackers.
Warlock, a suspected China-linked threat actor, has been continuing to weaponize Microsoft SharePoint vulnerabilities in attacks targeting organizations in Portuguese- and Spanish-speaking countries. According to the Symantec and Carbon Black Threat Hunter Team, Warlock has been exploiting these vulnerabilities, likely both old and new, to disable security tools and deploy ransomware on targeted systems. The activity has hit critical infrastructure, government, and education organizations, highlighting the severity of the threat posed by Warlock.
In the past two months, Longlegs has attacked at least four organizations, including two critical infrastructure operators, a regional government body, and a university. The victims were in Portuguese- and Spanish-speaking countries, spanning Europe, Africa, and Latin America. Warlock, also tracked as Gold Salem, Longlegs, and Storm-2603, gained prominence in mid-2025 in connection with the zero-day exploitation of the "ToolShell" SharePoint flaws to deploy ransomware on targeted systems.
Earlier this year, the group was linked to the compromise of SmarterTools by exploiting an unpatched SmarterMail instance. It has also relied on legitimate tools like Velociraptor for command-and-control (C2) and the bring your own vulnerable driver (BYOVD) technique to disarm security software running on a compromised host. According to Symantec, Warlock shares overlaps with older activity clusters known as CL-CRI-1040, CamoFei, and ChamelGang.
In one intrusion against a critical infrastructure operator, the attackers pushed a tool designed to disable security software to at least 40 hosts within about two hours, then deployed Warlock on at least 33 hosts by staging it in the domain's SYSVOL share, where ordinary domain replication delivered it to machines. Attacks mounted by Warlock have leveraged multiple vulnerabilities in on-premises Microsoft SharePoint Server deployments.
Upon successfully finding a way in, the threat actors have been found to drop web shells that can target multiple versions of SharePoint. The end goal of the web shell is to collect the SharePoint farm's ASP.NET machine keys, which are then abused to forge a validly signed payload and achieve remote code execution inside the SharePoint application pool. Some of the other observed tactics are listed below:
- Using DLL sideloading to load malicious code into memory.
- Downloading follow-on payloads from legitimate cloud file-sharing and storage services such as catbox.moe and wasabisys.com to fly under the radar.
- Abusing a legitimate-but-vulnerable driver K7RKScan.sys (CVE-2025-1055) as part of a BYOVD attack to disable security software. The same driver was previously exploited by DragonForce ransomware actors.
- Using living-off-the-land (LotL) tooling to perform reconnaissance and run commands on the compromised hosts. This includes the abuse of Microsoft Visual Studio Code's built-in tunnel feature to facilitate remote connections to infected systems.
- Staging payloads inside the compromised domain's SYSVOL share to deploy ransomware at scale.
As recently as July 22, 2026, the threat actors are said to have exploited SharePoint Server flaws to drop a web shell, conduct discovery, obtain arbitrary code execution inside the SharePoint application pool, deploy additional payloads, burrow deeper into the network, establish VS Code tunnels, terminate security software, and ultimately deploy the ransomware binary. The continued activity of Warlock, more than a year after Warlock ransomware first came to prominence, shows that exploitation of ToolShell and other related-SharePoint vulnerabilities remains a viable initial access route for attackers.
"The apparent recent focus on Portuguese- and Spanish-speaking countries suggests either an opportunistic targeting pattern driven by exposed, vulnerable SharePoint servers, or a more deliberate tasking," Symantec and Carbon Black said. "Longlegs' continued activity, more than a year after Warlock ransomware first came to prominence, shows that exploitation of ToolShell and other related-SharePoint vulnerabilities remains a viable initial access route for attackers."
Related Information:
https://www.ethicalhackingnews.com/articles/Warlocks-Exploitation-of-Microsoft-SharePoint-Vulnerabilities-A-Threat-to-Critical-Infrastructure-and-Organizations-ehn.shtml
https://thehackernews.com/2026/10/warlock-exploits-sharepoint-flaws-to.html
https://nvd.nist.gov/vuln/detail/CVE-2025-1055
https://www.cvedetails.com/cve/CVE-2025-1055/
Published: Sat Oct 3 11:34:43 2026 by llama3.2 3B Q4_K_M