VYPR
breachPublished Oct 2, 2026· 1 source

Warlock Expands SharePoint Exploitation in Critical Infrastructure Attacks

China-based threat actor Warlock continues to exploit Microsoft SharePoint vulnerabilities, targeting critical infrastructure and government entities with ransomware.

The Warlock ransomware group, believed to be operated by a China-based hacking collective tracked as Longlegs and Storm-2603, is actively expanding its exploitation of Microsoft SharePoint vulnerabilities. This campaign, ongoing since at least July 2025, has primarily targeted organizations within the critical infrastructure, government, and education sectors, according to recent reporting by Symantec.

Storm-2603 has a history of leveraging SharePoint flaws, notably its exploitation of two vulnerabilities, dubbed ToolShell, as zero-days. This activity was observed alongside other Chinese state-sponsored groups like Linen Typhoon and Violet Typhoon. Within weeks of the initial disclosure, hundreds of SharePoint servers were compromised, with Storm-2603's exploitation of ToolShell standing out due to its prevalence amidst other advanced persistent threat (APT) activities.

By October 2025, researchers identified numerous Warlock ransomware attacks that utilized the ToolShell vulnerability. Victims at that time included a Middle Eastern telecom firm, government entities in Africa and South America, and a US university. The continued focus on SharePoint underscores its effectiveness as an initial access vector for threat actors seeking to compromise sensitive systems.

Symantec's latest report indicates that Storm-2603 continues to favor SharePoint vulnerabilities. In addition to ToolShell, the group's arsenal now appears to include more recent flaws such as CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, CVE-2026-58644, CVE-2026-50522, and CVE-2026-55040. Over the past two months, the Warlock operator has targeted at least four organizations in Portuguese- and Spanish-speaking countries, including two critical infrastructure operators (a water utility and a telecommunications provider), a regional government body, and a university.

During one observed intrusion, the group deployed tools to disable security software on at least 40 systems before executing the Warlock ransomware on 33 of them. The typical post-exploitation chain involves deploying webshells, exfiltrating ASP.NET machine keys, and deploying a forced signed payload for remote code execution (RCE). Storm-2603 employs DLL sideloading for in-memory execution, retrieves additional payloads from legitimate file-sharing services, and uses vulnerable drivers to disable security tools.

The threat actor also leverages living-off-the-land tools for reconnaissance and command execution. Notably, the group has been observed abusing Visual Studio Code's built-in tunnel feature, installing the code-insiders.exe binary as a service to establish covert remote network access that can blend in with legitimate traffic from developer or administrator workstations. Furthermore, the Warlock payload is staged within the domain's SYSVOL share, which is automatically replicated across all domain controllers, enabling the ransomware to be executed at scale.

Symantec emphasizes that the continued activity of Longlegs, more than a year after Warlock ransomware first gained prominence, highlights that exploitation of ToolShell and related SharePoint vulnerabilities remains a viable initial access route for attackers targeting unpatched or unmitigated SharePoint deployments. This persistent threat underscores the ongoing need for organizations to maintain robust patch management and security configurations for their SharePoint environments.

Synthesized by Vypr AI