thehackernews.com 3 Oct 2026, 14:36 UTC

China-linked Warlock Exploits SharePoint to Deploy Ransomware Against Critical Sectors

CyberSIXT Evidence Panel Source marked as original reporting
CISA KEV Not in KEV
Patch Patch Status Unknown
Threat Actor

WARLOCK , a China-linked threat actor also known as Gold Salem, Longlegs and Storm-2603, continues to weaponise flaws in Microsoft SharePoint to gain initial access, disable security tooling and deploy ransomware. The activity, tracked by Symantec and Carbon Black Threat Hunter Team, has targeted organisations in Portuguese- and Spanish-speaking regions, including critical infrastructure, government and education sectors across Europe, Africa and Latin America.

In the most recent campaign, at least four organisations were affected within two months: two critical infrastructure operators (a water utility and a telecommunications provider), a regional government body and a university.

The attackers exploit on‑premises SharePoint Server vulnerabilities to drop web shells that can target multiple SharePoint versions. Once in, the objective is to harvest the farm’s ASP[.]NET machine keys, which are then abused to forge a validly signed payload and achieve remote code execution inside the SharePoint application pool.

Reported techniques include DLL sideloading, downloading follow‑on payloads from cloud services such as catbox[.]moe and wasabisys[.]com, and BYOVD using the K7RKScan[.]sys driver (CVE-2025-1055) to disable security software. The group has also used living‑off‑the‑land tools and hosted payloads in the SYSVOL share to scale ransomware deployment, with operations observed as recently as 22 July 2026.

Symantec and Carbon Black emphasise that exploitation of ToolShell and related SharePoint flaws remains a viable initial access route for unpatched deployments. The campaign’s focus on Portuguese‑ and Spanish‑speaking countries may reflect opportunistic targeting of exposed SharePoint servers or a broader tasking pattern.

View full article

Article by CyberSIXT