The Warlock ransomware group is ramping up its focus on SharePoint servers, launching attacks on vital sectors such as critical infrastructure, governmental bodies, and educational institutions. This surge in activities is documented by Symantec, which highlights the group’s persistent targeting strategies.
Background on Warlock’s Operations
Believed to be operated by a China-based hacking group known as Longlegs or Storm-2603, Warlock has a history of disruptive cyber activities. This group has been associated with various malicious campaigns, including CL-CRI-1040, CamoFei, and ChamelGang. Their tactics prominently feature exploiting vulnerabilities, particularly within SharePoint systems.
Last year, Chinese state-sponsored entities, Linen Typhoon and Violet Typhoon, were observed exploiting SharePoint vulnerabilities termed ToolShell. These zero-day vulnerabilities were targeted weeks before their public disclosure, resulting in the compromise of over 400 SharePoint servers amid a surge in advanced persistent threat (APT) activities.
Recent Exploitation and Targeted Sectors
By October 2025, researchers identified a series of Warlock ransomware attacks utilizing ToolShell vulnerabilities. The group’s targets included a telecommunications company in the Middle East, government bodies in Africa and South America, and a university in the United States. Symantec’s latest report underscores Storm-2603’s ongoing preference for exploiting SharePoint flaws, with an expanded arsenal potentially including several recent vulnerabilities identified as CVE-2026-32201 among others.
In the past two months alone, Warlock has targeted at least four organizations in Portuguese- and Spanish-speaking regions, including critical infrastructure operators, a water utility, a telecommunications provider, a regional government body, and a university.
Techniques and Future Threats
The group’s methodical exploitation process often involves deploying webshells, exfiltrating ASP.NET machine keys, and executing remote code via forced payloads. They employ DLL sideloading for in-memory execution, leveraging legitimate file-sharing services to drop additional payloads and disable security measures using vulnerable drivers.
Further complicating detection, Warlock utilizes Visual Studio Code’s built-in tunneling feature to establish hidden network access, blending in with typical traffic from developer or admin workstations. The ransomware is staged within the domain’s SYSVOL share, enabling wide-scale execution across domain controllers.
Symantec notes that Longlegs’ sustained activity, well over a year since Warlock’s initial rise, indicates that exploiting SharePoint vulnerabilities remains an effective entry point for attackers on unpatched systems. The enduring threat highlights the need for constant vigilance and timely patching to mitigate these risks.
For further reading, related cyber threats include tactics by Russian APT Star Blizzard, innovative uses of ChatGPT in attacks, and vulnerabilities exploited by Daemon Tools hackers.
