Executive Summary
Facts Only
* Warlock targets SharePoint servers in attacks against critical infrastructure, government, and education entities.
* Warlock is believed to be operated by the China-based hacking group Longlegs and Storm-2603.
* Chinese state-sponsored groups Linen Typhoon and Violet Typhoon exploited SharePoint vulnerabilities known as ToolShell as zero-days.
* More than 400 SharePoint servers were compromised in the period following exploitation of ToolShell.
* Warlock attacks in October 2025 targeted a Middle East telecom firm, African and South American government entities, and a US university.
* Storm-2603 continues to favor the exploitation of SharePoint bugs.
* Additional exploited flaws include CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, CVE-2026-58644, CVE-2026-50522, and CVE-2026-55040.
* The group deployed a tool to disable security software on at least 40 systems before executing Warlock on at least 33 of them.
* Exploitation methods included webshell deployment, ASP.NET machine key exfiltration, forced signed payload deployment for RCE, DLL sideloading, and dropping payloads from file-sharing services.
* The Warlock payload was staged in the domain’s SYSVOL share for scale execution.
Full Take
The narrative highlights a persistent pathway where unpatched SharePoint vulnerabilities serve as an initial access vector, which is then leveraged by sophisticated threat actors linked to state-sponsored groups for large-scale ransomware deployment against high-value targets. The reliance on exploiting known flaws like ToolShell, and subsequent leveraging of related CVEs, suggests that the technical weakness in patching protocols remains a critical operational vulnerability irrespective of specific exploit novelty. The methodology—combining initial access via zero-day-like flaws with multi-stage lateral movement techniques (DLL sideloading, living-off-the-land tools, domain share staging)—indicates an attacker mindset focused on deep persistence and systemic disruption rather than mere data exfiltration. Furthermore, the actor's observed use of developer tools to blend malicious activity into legitimate administrative traffic suggests a sophisticated attempt to evade signature-based detection by mimicking trusted internal workflows. The continued success of this approach across diverse international entities implies that defense strategies must move beyond patch management to focus on hardening the entire ecosystem against memory-level execution and trusted application behavior, recognizing that the exploitation chain itself is as important as the initial vulnerability.
Bridge Questions:
What mechanisms exist for organizations to detect and mitigate threats leveraging in-memory code execution techniques like DLL sideloading when standard endpoint detection focuses on file integrity? How can defense strategies account for the contextual blending of malicious activity within legitimate administrative toolsets, and what alternative monitoring systems are necessary to analyze anomalous interactions between services like Visual Studio Code and core network shares? What is the long-term impact of relying on vulnerability disclosure timelines versus proactive internal security posture management in mitigating risks associated with public SharePoint flaws?
From the original · SecurityWeek
The Warlock ransomware group continues to target SharePoint servers in attacks against critical infrastructure, government, and education entities, Symantec reports. Warlock is believed to be operated by a China-based hacking group tracked as Longlegs and Storm-2603, which has been linked to malicious operations such as CL-CRI-1040, CamoFei, and ChamelGang.Read the full story at securityweek.com
Sentinel — Human
The text reads like a professionally synthesized report based on existing threat intelligence, detailing technical exploitation methods and actor attribution.
