Warlock uses SharePoint flaws to disable defenses and spread ransomware

The China-linked threat actor known as Warlock has continued exploiting vulnerabilities in on-premises Microsoft SharePoint Server to disable security software and deploy ransomware. Symantec and the Carbon Black Threat Hunter Team observed attacks against at least four organizations in the past two months: two critical infrastructure operators, a regional government body and a university.
The victims included a water utility and a telecommunications provider, and were located in Portuguese- and Spanish-speaking countries across Europe, Africa and Latin America. Warlock is also tracked as Gold Salem, Longlegs and Storm-2603.
Fast ransomware deployment after SharePoint access
In one intrusion at a critical infrastructure operator, attackers distributed a tool intended to disable security software to at least 40 hosts in roughly two hours. They subsequently deployed the Warlock ransomware to at least 33 hosts by placing it in the domain's SYSVOL share, allowing normal domain replication to distribute it to machines.
The group has targeted multiple SharePoint Server vulnerabilities, potentially including both older and newer flaws. After gaining access, it drops web shells capable of targeting multiple SharePoint versions. Those web shells are used to collect the SharePoint farm's ASP.NET machine keys, enabling the attackers to forge a validly signed payload and obtain remote code execution within the SharePoint application pool.
Defense evasion and lateral movement techniques
Warlock has also used DLL sideloading to load malicious code into memory and downloaded additional payloads from legitimate cloud storage and file-sharing services, including catbox[.]moe and wasabisys[.]com. These methods can make follow-on activity less conspicuous while attackers extend their access.
Researchers observed the group abusing K7RKScan.sys, a legitimate but vulnerable driver associated with CVE-2025-1055, in a bring-your-own-vulnerable-driver attack designed to turn off security software. The same driver had previously been exploited by DragonForce ransomware actors. Warlock also uses living-off-the-land tools for reconnaissance and command execution.
Microsoft Visual Studio Code's built-in tunnel feature was abused to create remote connections to compromised systems. In activity recorded as recently as July 22, 2026, the attackers dropped a SharePoint web shell, conducted discovery, executed code in the application pool, deployed further payloads, moved deeper into the network, created VS Code tunnels, terminated security products and deployed ransomware.
Operational implications for SharePoint estates
Symantec and Carbon Black said the activity demonstrates that ToolShell and related SharePoint vulnerabilities remain a viable entry path where deployments have not been patched or otherwise mitigated. Organizations operating on-premises SharePoint should ensure relevant fixes or mitigations are in place and investigate unexpected web shells, access to ASP.NET machine keys, suspicious driver loads, VS Code tunnel use and unusual payloads placed in SYSVOL, because these signals can precede rapid domain-wide ransomware distribution.

