# Warlock Ransomware Targets Critical Sectors via SharePoint Vulnerabilities

*Published October 2, 2026*
*Source: [https://cybersecuritynews.com/warlock-ransomware-exploiting-sharepoint-flaws/](https://cybersecuritynews.com/warlock-ransomware-exploiting-sharepoint-flaws/)*

## Executive Summary

*This is a Premium edition. The Executive Summary is available to sec-news.ai members —*
*[read it here](https://www.sec-news.ai/news/warlock-ransomware-targets-critical-sectors-via-sharepoint-vulnerabilities) or [see plans](https://www.sec-news.ai/pricing).*

## Article

A cyber threat actor linked to China is exploiting vulnerabilities in Microsoft SharePoint Server to deploy Warlock ransomware, targeting essential service and public sector organizations in Portuguese and Spanish-speaking regions. Symantec refers to this group as Longlegs, while Microsoft uses the designation Storm-2603. This campaign has impacted a water utility, a telecommunications provider, a regional government, and a university across Europe, Africa, and Latin America over the past two months.

Warlock ransomware emerged in June 2025, gaining notoriety through the SharePoint 'ToolShell' exploit chain, which utilized CVE-2025-49704 and CVE-2025-49706. The Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that these exploits allow unauthorized access to SharePoint servers, exposing internal configurations and enabling remote code execution. Despite new SharePoint flaws disclosed in 2026, the attack surface remains vulnerable, prompting CISA to warn of ongoing exploitation.

The attackers often use an ASPX webshell in SharePoint's LAYOUTS directory to extract ASP.NET machine keys, allowing them to execute code within the SharePoint application pool. This is followed by loading additional malware through DLL sideloading with installers retrieved from services like Catbox and Wasabi, making their activity difficult to distinguish from legitimate cloud operations.

In a notable incident on July 22, 2026, attackers infiltrated critical infrastructure by deploying a webshell on a SharePoint server. They conducted extensive reconnaissance and used tools like NetExec for Active Directory exploration. Before encrypting data, they deployed an anti-virus and endpoint detection and response termination utility on numerous hosts, exploiting a vulnerable driver tracked as CVE-2025-1055.

The ransomware payload was quickly distributed across 33 systems by leveraging the SYSVOL share, which replicates across domain controllers. This tactic turned trusted Active Directory infrastructure into a formidable ransomware delivery mechanism. The campaign underscores the need for more than just patching in the face of SharePoint exploitation. Organizations should actively search for webshells, rotate machine keys, enable AMSI in full mode, and deploy endpoint detection technologies to mitigate risks.
