// AI threat desk · 4 Oct 2026
Home/CVE · Vulns & Patches
Vulns & PatchesHighRANSOMCVSS not assigned

Microsoft SharePoint targeted by Warlock in ongoing ransomware campaign

Warlock hit at least four organizations in Portuguese- and Spanish-speaking countries over the past two months, Symantec said.

AI-generated image of security analysts monitoring blurred document-management systems in a dark operations centre.
AI-generated image, not a photo of the event.
Key takeaways
  • Symantec said Warlock hit at least four organizations in Portuguese- and Spanish-speaking countries over the past two months.
  • Symantec said victims included two critical infrastructure operators, a water utility, a telecommunications provider, a regional government body and a university.
  • SecurityWeek reported that attackers disabled security software on at least 40 systems and executed Warlock on at least 33.

Warlock continued targeting Microsoft SharePoint servers, Symantec said, hitting at least four organizations in Portuguese- and Spanish-speaking countries over the past two months.

Symantec said the victims included two critical infrastructure operators, a water utility, a telecommunications provider, a regional government body and a university. In one intrusion, SecurityWeek reported, attackers disabled security software on at least 40 systems and executed Warlock on at least 33.

Symantec linked Warlock to the China-based hacking group Longlegs, also tracked as Storm-2603.

On this page

SharePoint exploitation preceded webshell deployment and remote code execution

Symantec said the group typically followed SharePoint exploitation with webshell deployment, ASP.NET machine-key exfiltration and a signed payload for remote code execution.

Trend Micro said attackers gained code execution, escalated privileges, moved laterally and delivered ransomware at scale by exploiting SharePoint authentication and deserialization flaws.

Warlock disabled security software before deploying across hosts

Symantec said attackers pushed a tool designed to disable security software to at least 40 hosts within about two hours, then staged Warlock in the domain’s SYSVOL share and deployed it on at least 33 hosts.

Symantec said the group used the legitimate but vulnerable K7RKScan.sys driver, identified as CVE-2025-1055, in a bring-your-own-vulnerable-driver attack to disable security software.

Trend Micro said the attackers created a new Group Policy Object to establish higher privileges after entering a network.

Warlock has used SharePoint flaws since its 2025 emergence

Symantec said Warlock emerged in June 2025 and gained attention after attackers used zero-day vulnerabilities in Microsoft SharePoint Server known as ToolShell. It said the flaws were CVE-2025-49704, CVE-2025-49706, CVE-2025-53770 and CVE-2025-53771.

The Record reported that the attacks continued into 2026 and included newer SharePoint vulnerabilities highlighted by the U.S. government. CISA said those vulnerabilities affected all supported on-premises SharePoint Server versions, including Subscription Edition, 2019 and 2016, and enabled remote code execution and post-exploitation activity.

The Record said Warlock had previously been used against organizations in the U.S., Russia, Brazil, India, Taiwan and Japan.

Trend Micro urged organizations to promptly patch their on-premises SharePoint servers and deploy layered detection capabilities against the Warlock threat.

CISA also urged organizations to apply Microsoft’s latest SharePoint patches and security updates, verify successful installation and shorten patching cycles when possible.

What to do now

  1. Apply the latest patches and security updates from Microsoft, verify that installation completes successfully and shorten patching cycles when possible.
  2. Avoid exposing SharePoint Servers directly to the internet.
  3. Promptly patch on-premises SharePoint servers and deploy layered detection capabilities.

FAQ

What happened in the Warlock SharePoint campaign?

Symantec said Warlock hit at least four organizations in Portuguese- and Spanish-speaking countries over the past two months.

Who was targeted by Warlock?

Symantec said the victims included two critical infrastructure operators, a water utility, a telecommunications provider, a regional government body and a university.

How did Warlock use compromised SharePoint servers?

Symantec said the attackers typically followed SharePoint exploitation with webshell deployment, machine-key exfiltration and a signed payload for remote code execution.

Was Warlock exploitation confirmed?

Microsoft reported that Storm-2603 was distributing Warlock ransomware on exploited SharePoint on-premises servers.

How can organizations respond to the Warlock SharePoint threat?

CISA urged organizations to apply Microsoft’s latest SharePoint patches and security updates, verify successful installation and avoid exposing SharePoint Servers directly to the internet.

What is the ToolShell connection to Warlock?

Symantec said Warlock gained prominence after attackers used zero-day Microsoft SharePoint Server vulnerabilities known as ToolShell. The listed flaws were CVE-2025-49704, CVE-2025-49706, CVE-2025-53770 and CVE-2025-53771.

Sources

  1. Warlock Ransomware Attackers Hit Water and Telecom Operators, SymantecPrimary
  2. CISA Urges SharePoint Hardening After New Exploitations | CISA, CISAPrimary
  3. SYSVOL Directory, NetwrixPrimary
  4. Warlock Expands SharePoint Exploitation in Critical Infrastructure Attacks, SecurityWeek
  5. 'Warlock' ransomware used in attacks on critical infrastructure in Portuguese, Spanish-speaking countries, The Record
  6. Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware, The Hacker News
  7. Warlock Ransomware Hitting Victims Globally Through SharePoint ToolShell Exploit, Trend Micro
How we checked this story
ClaimSourceStatus
SecurityWeek reported that Warlock continued targeting SharePoint servers in attacks against critical infrastructure, government and education entities.SecurityWeekAttributed
Symantec linked Warlock to the China-based hacking group Longlegs, also tracked as Storm-2603.Symantec, via SecurityWeekAttributed
Symantec said the victims included two critical infrastructure operators, a water utility, a telecommunications provider, a regional government body and a university.Symantec, via SecurityWeekAttributed
SecurityWeek said in one intrusion, attackers disabled security software on at least 40 systems and executed Warlock on at least 33 of them.SecurityWeekAttributed
Symantec said the attackers typically followed SharePoint exploitation with webshell deployment, machine-key exfiltration and a signed payload for remote code execution.Symantec, via SecurityWeekAttributed
The Hacker News reported that Warlock is also tracked as Gold Salem, Longlegs and Storm-2603.The Hacker NewsAttributed
The Hacker News said Warlock gained prominence in mid-2025 through zero-day exploitation of ToolShell SharePoint flaws.The Hacker NewsAttributed
Symantec said the attackers pushed a security-disabling tool to at least 40 hosts within about two hours and deployed Warlock on at least 33 hosts through SYSVOL.Symantec, via The Hacker NewsAttributed
Symantec said the attackers used the vulnerable K7RKScan.sys driver, identified as CVE-2025-1055, to disable security software.Symantec, via The Hacker NewsAttributed
CISA said threat actors were actively exploiting six SharePoint vulnerabilities to gain unauthorized access to on-premises SharePoint Server instances.CISAConfirmed
CISA said the six vulnerabilities affect all supported on-premises SharePoint Server versions and enable remote code execution and post-exploitation activity.CISAConfirmed
The intrusion’s first observed malicious activity occurred on July 22, 2026, when a webshell was installed on a SharePoint server.SymantecConfirmed
Warlock first became prominent through exploitation of Microsoft SharePoint ToolShell vulnerabilities in 2025.SymantecConfirmed
The ToolShell vulnerabilities were CVE-2025-49704, CVE-2025-49706, CVE-2025-53770 and CVE-2025-53771.SymantecConfirmed
The Record reported that the victims were located across Europe, Africa and Latin America.The RecordAttributed
Symantec researchers said the apparent focus on Portuguese- and Spanish-speaking countries could reflect opportunistic targeting or deliberate tasking.Symantec, via The RecordAttributed
The Record said the attackers used a tool to disable security software on dozens of hosts before deploying Warlock ransomware.The RecordAttributed
The Record reported that the campaign continued into 2026 and included newer SharePoint vulnerabilities highlighted by the U.S. government.The RecordAttributed
The Record said CISA published a warning one month earlier that hackers were exploiting six new SharePoint vulnerabilities.The RecordAttributed
The Record said Warlock had previously been used against organizations in the United States, Russia, Brazil, India, Taiwan and Japan.The RecordAttributed
The Hacker News said Warlock was previously linked to the compromise of SmarterTools through an unpatched SmarterMail instance.The Hacker NewsAttributed
The Hacker News said Warlock used Velociraptor for command-and-control and BYOVD to disarm security software.The Hacker NewsAttributed
The Hacker News reported that SharePoint exploitation was observed as recently as July 22, 2026.The Hacker NewsAttributed
Trend Micro said attackers gained code execution, escalated privileges, moved laterally and delivered ransomware at scale through SharePoint authentication and deserialization flaws.Trend MicroAttributed
Microsoft reported on July 23 that Storm-2603 was distributing Warlock ransomware on exploited SharePoint on-premises servers.MicrosoftAttributed
Trend Micro said Warlock made its public debut on the Russian-language RAMP forum in early June 2025.Trend MicroAttributed
Trend Micro said Warlock’s mid-2025 victim list covered North America, Europe, Asia and Africa and included technology and critical infrastructure industries.Trend MicroAttributed
Infosecurity Magazine said warlock claimed responsibility for an August 2025 attack on UK telecommunications company Colt Technology Services.Infosecurity MagazineAttributed
Trend Micro said attackers created a new Group Policy Object to establish higher privileges after entering a network.Trend MicroAttributed
CISA published its report on Aug 26, 2026.CISAConfirmed
netwrix.com published its report on Jan 30, 2017.netwrix.comConfirmed

Could not verify

  • Whether the Warlock campaign exploited each of the six newer SharePoint CVEs is not established.
  • Whether the attackers were directed by the Chinese state is not established.
  • How many organizations were affected beyond the four reported victims is not established.
Explore with AI