Skip to content

Executive Summary

The Warlock ransomware group targets SharePoint servers across critical infrastructure, government, and education sectors. The group is believed to be linked to the China-based hacking groups Longlegs and Storm-2603. Previous activity involved state-sponsored groups like Linen Typhoon and Violet Typhoon exploiting SharePoint vulnerabilities. Researchers found numerous Warlock attacks exploiting ToolShell in October 2025, affecting victims including a Middle East telecom firm, African and South American government entities, and a US university. The group utilized methods such as deploying security software disabling tools, exfiltrating machine keys, deploying forced signed payloads for remote code execution (RCE), and leveraging DLL sideloading for in-memory execution. Further attack methods involved dropping payloads from file-sharing services, using vulnerable drivers to disable security tools, employing living-off-the-land tools for reconnaissance, and abusing Visual Studio Code features to establish covert access. The ransomware payload was staged in the SYSVOL share for mass execution across domain controllers.

Facts Only

* Warlock targets SharePoint servers in attacks against critical infrastructure, government, and education entities.
* Warlock is believed to be operated by the China-based hacking group Longlegs and Storm-2603.
* Chinese state-sponsored groups Linen Typhoon and Violet Typhoon exploited SharePoint vulnerabilities known as ToolShell as zero-days.
* More than 400 SharePoint servers were compromised in the period following exploitation of ToolShell.
* Warlock attacks in October 2025 targeted a Middle East telecom firm, African and South American government entities, and a US university.
* Storm-2603 continues to favor the exploitation of SharePoint bugs.
* Additional exploited flaws include CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, CVE-2026-58644, CVE-2026-50522, and CVE-2026-55040.
* The group deployed a tool to disable security software on at least 40 systems before executing Warlock on at least 33 of them.
* Exploitation methods included webshell deployment, ASP.NET machine key exfiltration, forced signed payload deployment for RCE, DLL sideloading, and dropping payloads from file-sharing services.
* The Warlock payload was staged in the domain’s SYSVOL share for scale execution.

Full Take

The narrative highlights a persistent pathway where unpatched SharePoint vulnerabilities serve as an initial access vector, which is then leveraged by sophisticated threat actors linked to state-sponsored groups for large-scale ransomware deployment against high-value targets. The reliance on exploiting known flaws like ToolShell, and subsequent leveraging of related CVEs, suggests that the technical weakness in patching protocols remains a critical operational vulnerability irrespective of specific exploit novelty. The methodology—combining initial access via zero-day-like flaws with multi-stage lateral movement techniques (DLL sideloading, living-off-the-land tools, domain share staging)—indicates an attacker mindset focused on deep persistence and systemic disruption rather than mere data exfiltration. Furthermore, the actor's observed use of developer tools to blend malicious activity into legitimate administrative traffic suggests a sophisticated attempt to evade signature-based detection by mimicking trusted internal workflows. The continued success of this approach across diverse international entities implies that defense strategies must move beyond patch management to focus on hardening the entire ecosystem against memory-level execution and trusted application behavior, recognizing that the exploitation chain itself is as important as the initial vulnerability.
Bridge Questions:
What mechanisms exist for organizations to detect and mitigate threats leveraging in-memory code execution techniques like DLL sideloading when standard endpoint detection focuses on file integrity? How can defense strategies account for the contextual blending of malicious activity within legitimate administrative toolsets, and what alternative monitoring systems are necessary to analyze anomalous interactions between services like Visual Studio Code and core network shares? What is the long-term impact of relying on vulnerability disclosure timelines versus proactive internal security posture management in mitigating risks associated with public SharePoint flaws?

From the original · SecurityWeek

The Warlock ransomware group continues to target SharePoint servers in attacks against critical infrastructure, government, and education entities, Symantec reports. Warlock is believed to be operated by a China-based hacking group tracked as Longlegs and Storm-2603, which has been linked to malicious operations such as CL-CRI-1040, CamoFei, and ChamelGang.
Read the full story at securityweek.com

Sentinel — Human

Confidence

The text reads like a professionally synthesized report based on existing threat intelligence, detailing technical exploitation methods and actor attribution.

Signals Detected
low severity: Moderate sentence length variance; uses specific technical terminology effectively without excessive uniformity.
low severity: Strong, linear flow of cause-and-effect, typical of threat reporting. Attribution to Symantec is clear.
low severity: Follows a standard investigative pattern: actor identification -> past exploits -> current methods -> impact. Uses direct quotes effectively.
low severity: Specific CVE numbers and group names are present, suggesting reliance on verifiable reporting rather than pure fabrication.
Human Indicators
Incorporates specific, rapidly evolving threat intelligence (CVEs, group names) that requires human aggregation; the structure flows like a detailed security briefing.
Warlock Expands SharePoint Exploitation in Critical Infrastructure Attacks | Huntaegis