securityaffairs.com 4 Oct 2026, 07:49 UTC

Warlock Ransomware Exploits SharePoint Flaws to Hit Critical Infrastructure

Warlock Ransomware Exploits SharePoint Flaws to Hit Critical Infrastructure
CyberSIXT Evidence Panel Source marked as original reporting
Threat Actor
🇨🇳 Storm-2603

SYMANTEC’S report confirms that Warlock ransomware, linked to Longlegs (Storm-2603) and tied to older China-nexus clusters, continues to exploit a chain of SharePoint flaws known as ToolShell to breach critical infrastructure. In a run of attacks over July 2026, attackers compromised a water utility, a telecom provider, a regional government body and a university, with victims in Portuguese- and Spanish-speaking countries across Europe, Africa and Latin America.

The intrusion begins with a webshell placed in the SharePoint LAYOUTS directory, followed by theft of the server’s ASP[.]NET machine keys to forge a signed payload that executes within SharePoint. The group then uses DLL sideloading and pulls additional payloads from legitimate hosting services (for example catbox[.]moe and wasabisys[.]com) to blend traffic with normal activity.

Once inside, the attackers disable security tools using a vulnerable signed driver named K7RKScan and establish remote access by installing Visual Studio Code’s tunneling feature as a service. Symantec’s investigation traces rapid lateral movement: after disabling protection, Warlock is deployed to multiple hosts via the domain’s SYSVOL share, with dfsrs[.]exe distributing the malicious files across domain controllers.

They also documented the use of a deserialization gadget to turn a forged, signed payload into code execution, followed by the deployment of three installer packages within ninety minutes. By 31 July, a tool designed to disable AV/EDR had been pushed to around 40 hosts before Warlock was installed on at least 33 machines.

The incident underscores that ToolShell remains a viable initial access method where SharePoint patches and mitigations are missing, and cites the need to review on‑premises SharePoint against the July 2026 CISA advisory.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline