Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Warlock Group Intensifies SharePoint Attacks on Key Sectors

Warlock Group Intensifies SharePoint Attacks on Key Sectors

Posted on October 2, 2026 By CWS

The Warlock ransomware group is ramping up its focus on SharePoint servers, launching attacks on vital sectors such as critical infrastructure, governmental bodies, and educational institutions. This surge in activities is documented by Symantec, which highlights the group’s persistent targeting strategies.

Background on Warlock’s Operations

Believed to be operated by a China-based hacking group known as Longlegs or Storm-2603, Warlock has a history of disruptive cyber activities. This group has been associated with various malicious campaigns, including CL-CRI-1040, CamoFei, and ChamelGang. Their tactics prominently feature exploiting vulnerabilities, particularly within SharePoint systems.

Last year, Chinese state-sponsored entities, Linen Typhoon and Violet Typhoon, were observed exploiting SharePoint vulnerabilities termed ToolShell. These zero-day vulnerabilities were targeted weeks before their public disclosure, resulting in the compromise of over 400 SharePoint servers amid a surge in advanced persistent threat (APT) activities.

Recent Exploitation and Targeted Sectors

By October 2025, researchers identified a series of Warlock ransomware attacks utilizing ToolShell vulnerabilities. The group’s targets included a telecommunications company in the Middle East, government bodies in Africa and South America, and a university in the United States. Symantec’s latest report underscores Storm-2603’s ongoing preference for exploiting SharePoint flaws, with an expanded arsenal potentially including several recent vulnerabilities identified as CVE-2026-32201 among others.

In the past two months alone, Warlock has targeted at least four organizations in Portuguese- and Spanish-speaking regions, including critical infrastructure operators, a water utility, a telecommunications provider, a regional government body, and a university.

Techniques and Future Threats

The group’s methodical exploitation process often involves deploying webshells, exfiltrating ASP.NET machine keys, and executing remote code via forced payloads. They employ DLL sideloading for in-memory execution, leveraging legitimate file-sharing services to drop additional payloads and disable security measures using vulnerable drivers.

Further complicating detection, Warlock utilizes Visual Studio Code’s built-in tunneling feature to establish hidden network access, blending in with typical traffic from developer or admin workstations. The ransomware is staged within the domain’s SYSVOL share, enabling wide-scale execution across domain controllers.

Symantec notes that Longlegs’ sustained activity, well over a year since Warlock’s initial rise, indicates that exploiting SharePoint vulnerabilities remains an effective entry point for attackers on unpatched systems. The enduring threat highlights the need for constant vigilance and timely patching to mitigate these risks.

For further reading, related cyber threats include tactics by Russian APT Star Blizzard, innovative uses of ChatGPT in attacks, and vulnerabilities exploited by Daemon Tools hackers.

Security Week News Tags:APT, China-based hackers, critical infrastructure, cyber attacks, Cybersecurity, Longlegs, Ransomware, security vulnerabilities, SharePoint, Storm-2603, Symantec, Warlock

Post navigation

Previous Post: Kiteworks Enhances Security with Major Update Fixing 126 Vulnerabilities
Next Post: Cloudflare to Offer Free Digital Certificates Globally

Related Posts

Discern Security Secures M in Series A Funding Discern Security Secures $13M in Series A Funding Security Week News
CISA Urges Agencies to Address High-Risk Security Flaws CISA Urges Agencies to Address High-Risk Security Flaws Security Week News
IoT Security Firm Exein Raises  Million  IoT Security Firm Exein Raises $81 Million  Security Week News
Fuji Electric HMI Configurator Flaws Expose Industrial Organizations to Hacking Fuji Electric HMI Configurator Flaws Expose Industrial Organizations to Hacking Security Week News
Chrome 147 Fixes 60 Security Flaws, Two Critical Chrome 147 Fixes 60 Security Flaws, Two Critical Security Week News
Iran’s Digital Warfare Tactics: A Comprehensive Analysis Iran’s Digital Warfare Tactics: A Comprehensive Analysis Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Cloudflare to Offer Free Digital Certificates Globally
  • Warlock Group Intensifies SharePoint Attacks on Key Sectors
  • Kiteworks Enhances Security with Major Update Fixing 126 Vulnerabilities
  • AI Agents Target US and Canadian Government Websites
  • U.S. Treasury Takes Action Against ATM Jackpotting Ring

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Cloudflare to Offer Free Digital Certificates Globally
  • Warlock Group Intensifies SharePoint Attacks on Key Sectors
  • Kiteworks Enhances Security with Major Update Fixing 126 Vulnerabilities
  • AI Agents Target US and Canadian Government Websites
  • U.S. Treasury Takes Action Against ATM Jackpotting Ring

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark