Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Warlock Group Targets SharePoint Flaws for Ransomware Attacks

Warlock Group Targets SharePoint Flaws for Ransomware Attacks

Posted on October 3, 2026 By CWS

A threat actor group, Warlock, believed to be linked to China, has been actively exploiting vulnerabilities in Microsoft SharePoint to launch attacks on organizations in countries where Portuguese and Spanish are spoken. The activity, identified by Symantec and Carbon Black, has targeted a variety of sectors, including critical infrastructure, government, and education.

Impact on Critical Sectors

In recent months, Warlock, also known as Gold Salem, Longlegs, and Storm-2603, has intensified its operations. Notably, it has attacked at least four organizations, as reported by Broadcom’s cybersecurity division. These attacks have affected two critical infrastructure operators, a regional government entity, and a university across Europe, Africa, and Latin America.

Warlock’s notoriety rose in 2025 due to its use of zero-day exploits in SharePoint, particularly with the ‘ToolShell’ flaws, to deploy ransomware. This year, they were implicated in the breach of SmarterTools by exploiting an unpatched SmarterMail instance. They also use legitimate tools like Velociraptor for command-and-control and the bring your own vulnerable driver (BYOVD) method to disable security software.

Tactics and Techniques

Warlock’s attack strategies involve exploiting multiple vulnerabilities in on-premises SharePoint Server setups. Once inside, they deploy web shells to target various SharePoint versions. The main goal is to collect ASP.NET machine keys, allowing them to forge a validly signed payload and gain remote code execution within the SharePoint environment.

The group employs several sophisticated techniques, such as DLL sideloading to introduce malicious code, downloading additional payloads from legitimate cloud services to avoid detection, and using vulnerable drivers to disable security tools. Additionally, they leverage ‘living-off-the-land’ techniques, such as using Microsoft Visual Studio Code’s tunnel feature for remote access.

Ongoing Threat and Response

By July 2026, Warlock continued exploiting SharePoint Server flaws to deploy web shells, enabling them to conduct network reconnaissance, execute arbitrary code, and distribute further payloads, including ransomware. Their attacks emphasize the necessity for patched and secure SharePoint deployments to prevent malicious breaches.

Symantec and Carbon Black highlight the ongoing threat, noting that these vulnerabilities remain a significant risk for unpatched SharePoint systems, particularly those in Portuguese and Spanish-speaking regions. This pattern could indicate either opportunistic exploitation or a more targeted approach based on exposed systems.

To mitigate these risks, organizations are encouraged to update their security measures, patch vulnerabilities promptly, and remain vigilant against sophisticated threat actors like Warlock.

The Hacker News Tags:BYOVD, critical infrastructure, cyber attacks, Cybersecurity, Hacking, Microsoft, Portuguese-speaking countries, Ransomware, security tools, SharePoint, Spanish-speaking countries, Threat Actors, Vulnerabilities, Warlock, web shells

Post navigation

Previous Post: Microsoft Releases Critical Exchange Update for Security Flaw
Next Post: Addressing Cybersecurity in an Era of Connected Vehicles

Related Posts

North Korean Hackers Exploit GitHub in South Korea Cyber Attacks North Korean Hackers Exploit GitHub in South Korea Cyber Attacks The Hacker News
Anthropic Reports Fourth AI Security Breach with Claude Model Anthropic Reports Fourth AI Security Breach with Claude Model The Hacker News
FakeGit Exploits GitHub to Distribute SmartLoader Malware FakeGit Exploits GitHub to Distribute SmartLoader Malware The Hacker News
Microsoft Highlights Hotel Phishing Threat with Node.js Microsoft Highlights Hotel Phishing Threat with Node.js The Hacker News
Meta Shuts Down 150K Accounts in Global Anti-Scam Effort Meta Shuts Down 150K Accounts in Global Anti-Scam Effort The Hacker News
Adobe Commerce Flaw CVE-2025-54236 Lets Hackers Take Over Customer Accounts Adobe Commerce Flaw CVE-2025-54236 Lets Hackers Take Over Customer Accounts The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • ShinyHunters Suspect in Jordan Assists FBI in Hack Probe
  • Addressing Cybersecurity in an Era of Connected Vehicles
  • Warlock Group Targets SharePoint Flaws for Ransomware Attacks
  • Microsoft Releases Critical Exchange Update for Security Flaw
  • MI5 Warns of China’s Influence on UK Academics

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • ShinyHunters Suspect in Jordan Assists FBI in Hack Probe
  • Addressing Cybersecurity in an Era of Connected Vehicles
  • Warlock Group Targets SharePoint Flaws for Ransomware Attacks
  • Microsoft Releases Critical Exchange Update for Security Flaw
  • MI5 Warns of China’s Influence on UK Academics

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark