
Warlock Gang Exploits SharePoint Flaws to Disable Defenses
Attackers tracked as Warlock are exploiting Microsoft SharePoint flaws to disable security tools and deploy ransomware against critical infrastructure, governme…
A threat actor known as Warlock is still using vulnerabilities in on-premises Microsoft SharePoint Server deployments to switch off security software and push ransomware onto victims, according to new telemetry and analysis published by Symantec and the Carbon Black Threat Hunter Team, which are part of Broadcom. The group, suspected of having links to China and also tracked as Gold Salem, Longlegs, and Storm-2603, has recently hit organizations in Portuguese- and Spanish-speaking countries across Europe, Africa, and Latin America, including critical infrastructure operators, government bodies, and universities.
Symantec and Carbon Black say the activity has continued into the past two months, with at least four known victims. Two of those were operators of critical infrastructure: a water utility and a telecommunications provider. The other victims were a regional government body and a university. The researchers note that Warlock first gained widespread attention in mid-2025, when it exploited zero-day flaws in a set of SharePoint vulnerabilities known as ToolShell to deliver ransomware. Earlier this year, the group was linked to compromising SmarterTools through an unpatched SmarterMail installation. It has also used legitimate remote-management software such as Velociraptor for command-and-control, and it has relied on a technique called bring your own vulnerable driver, or BYOVD, to turn off security products on infected machines. Symantec also said the group shares overlaps with older activity clusters known as CL-CRI-1040, CamoFei, and ChamelGang.
The researchers described one intrusion against a critical infrastructure operator in which the attackers pushed a tool designed to disable security software to at least 40 computers within about two hours. They then staged the Warlock ransomware inside the domain's SYSVOL share, a special network folder that Windows uses to automatically copy files to every machine in the organization. This allowed ordinary domain replication to deliver the ransomware to at least 33 hosts, turning a routine network process into a distribution channel for malware.
The attack chain begins when Warlock finds a way into an on-premises SharePoint Server, often through known vulnerabilities that have not been patched. Once inside, the attackers drop a web shell, which is a small malicious program that gives them a browser-based control panel on the hacked server. Symantec observed that the web shells can target multiple versions of SharePoint. The main goal of the web shell is to steal the SharePoint farm's ASP.NET machine keys. Those keys are secret values that the server uses to verify the authenticity of web requests and data. If the attackers obtain them, they can forge a validly signed payload and achieve remote code execution inside the SharePoint application pool, which is the part of the server that runs SharePoint's web pages.
From there, the group uses several stealth techniques. It abuses DLL sideloading to load malicious code into memory without writing obvious files to disk. It downloads follow-on payloads from legitimate cloud file-sharing and storage services such as catbox.moe and wasabisys.com, so the traffic looks like normal outbound activity to those services. Symantec and Carbon Black also found that Warlock abuses a legitimate but vulnerable driver named K7RKScan.sys, identified as CVE-2025-1055, as part of a BYOVD attack to disable security software. The same driver was previously exploited by DragonForce ransomware actors. The attackers also use living-off-the-land tooling, meaning they rely on built-in or trusted system tools instead of custom malware, to perform reconnaissance and run commands. One example is abusing the built-in tunnel feature in Microsoft Visual Studio Code to create remote connections to infected systems.
On July 22, 2026, the researchers observed the full chain in action. The threat actors exploited SharePoint Server flaws to drop a web shell, conducted discovery, obtained arbitrary code execution inside the SharePoint application pool, deployed additional payloads, burrowed deeper into the network, established Visual Studio Code tunnels, terminated security software, and ultimately deployed the ransomware binary. Symantec and Carbon Black said the group's continued activity, more than a year after Warlock ransomware first came to prominence, shows that exploitation of ToolShell and other related SharePoint vulnerabilities remains a viable initial access route for attackers targeting SharePoint deployments that have not been patched or otherwise mitigated. They added that the recent focus on Portuguese- and Spanish-speaking countries suggests either an opportunistic pattern driven by exposed vulnerable SharePoint servers or a more deliberate tasking.
For website owners and IT teams, the key takeaway is that unpatched on-premises SharePoint servers remain an attractive target, especially when they are exposed to the internet. The attacks show how quickly a single entry point can be turned into a network-wide ransomware deployment, partly by abusing legitimate Windows features such as SYSVOL replication and Visual Studio Code tunnels. Organizations should treat any sign of security software being disabled as an emergency, because Warlock has demonstrated that this step often happens within hours, before the ransomware is pushed to dozens of machines. For teams that need help assessing exposure on their own servers or tightening security around on-premises infrastructure, AEU-I offers security-first IT and infrastructure consulting.
How to Protect Yourself
- If your organization uses Microsoft SharePoint Server, apply the latest security updates from Microsoft right away and set a reminder to check for updates every month.
- Limit access to your SharePoint server so it is not reachable from the internet unless absolutely necessary, and use a secure gateway for remote access.
- Back up your website and files regularly to a separate location that is not connected to your main network, so you can restore them if ransomware locks your data.
- Turn on two-step login for all administrator accounts, so even a stolen password is not enough for an attacker to get in.
- If your antivirus or security software suddenly turns off or stops updating, report it to your IT team immediately, as attackers may be preparing to deploy ransomware.
Vulnerabilities & Fixes
- CVE-2025-1055 CVE-2025-1055 is the identifier for the vulnerable K7RKScan.sys driver that Symantec observed Warlock abusing to disable security software in bring your own vulnerable driver attacks. View the fix & details →
Terms Explained
- SharePoint Microsoft's software for building internal websites and document-sharing portals that many companies run on their own servers.
- Web shell A small malicious program that attackers place on a server to let them send commands and control it remotely through a web browser.
- ASP.NET machine keys Secret codes that a SharePoint server uses to verify that web requests and data are genuine; if stolen, attackers can forge trusted requests.
- DLL sideloading A trick where malware hides inside a legitimate-looking program file so the computer loads it without realizing it is malicious.
- BYOVD (bring your own vulnerable driver) An attack where criminals install an outdated or flawed driver on a computer to switch off its security software.
- SYSVOL share A special folder on a Windows network that automatically copies files to every computer in the organization, which attackers can misuse to spread malware.