WARLOCK , a ransomware operation tied to the China-based groups Longlegs and Storm-2603, is again exploiting SharePoint vulnerabilities to target critical infrastructure, government, and educational sectors.
Symantec’s assessment states that the group has been active against SharePoint since July 2025, with recent campaigns hitting at least four organisations in Portuguese- and Spanish-speaking regions, including two critical infrastructure operators, a water utility, a telecommunications provider, a regional government body, and a university.
In many intrusions, Warlock uses a pattern of webshell deployment, ASP[.]NET machine key exfiltration, and the introduction of a forced signed payload to achieve remote code execution after initial access through vulnerable SharePoint instances.
The attackers have expanded their toolkit beyond ToolShell, leveraging several recent SharePoint flaws and DLL sideloading to facilitate in-memory execution, followed by payload deployment via legitimate file-sharing and storage services. They are also observed staging the Warlock payload inside the domain’s SYSVOL share to enable wide-scale encryption across domain controllers.
Symantec notes additional techniques such as abusing Visual Studio Code’s tunnel feature to establish covert remote access and disabling security tools on compromised machines, including at least 40 systems in one operation. The campaign highlights that exploitation of ToolShell and other SharePoint vulnerabilities remains a viable initial access route for unpatched deployments. Relevant vulnerabilities cited include CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, CVE-2026-58644, CVE-2026-50522, and CVE-2026-55040. 2 October 2026.