Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Warlock Group Targets SharePoint Flaws for Ransomware Attacks

Warlock Group Targets SharePoint Flaws for Ransomware Attacks

Posted on October 3, 2026 By CWS

A threat actor group, Warlock, believed to be linked to China, has been actively exploiting vulnerabilities in Microsoft SharePoint to launch attacks on organizations in countries where Portuguese and Spanish are spoken. The activity, identified by Symantec and Carbon Black, has targeted a variety of sectors, including critical infrastructure, government, and education.

Impact on Critical Sectors

In recent months, Warlock, also known as Gold Salem, Longlegs, and Storm-2603, has intensified its operations. Notably, it has attacked at least four organizations, as reported by Broadcom’s cybersecurity division. These attacks have affected two critical infrastructure operators, a regional government entity, and a university across Europe, Africa, and Latin America.

Warlock’s notoriety rose in 2025 due to its use of zero-day exploits in SharePoint, particularly with the ‘ToolShell’ flaws, to deploy ransomware. This year, they were implicated in the breach of SmarterTools by exploiting an unpatched SmarterMail instance. They also use legitimate tools like Velociraptor for command-and-control and the bring your own vulnerable driver (BYOVD) method to disable security software.

Tactics and Techniques

Warlock’s attack strategies involve exploiting multiple vulnerabilities in on-premises SharePoint Server setups. Once inside, they deploy web shells to target various SharePoint versions. The main goal is to collect ASP.NET machine keys, allowing them to forge a validly signed payload and gain remote code execution within the SharePoint environment.

The group employs several sophisticated techniques, such as DLL sideloading to introduce malicious code, downloading additional payloads from legitimate cloud services to avoid detection, and using vulnerable drivers to disable security tools. Additionally, they leverage ‘living-off-the-land’ techniques, such as using Microsoft Visual Studio Code’s tunnel feature for remote access.

Ongoing Threat and Response

By July 2026, Warlock continued exploiting SharePoint Server flaws to deploy web shells, enabling them to conduct network reconnaissance, execute arbitrary code, and distribute further payloads, including ransomware. Their attacks emphasize the necessity for patched and secure SharePoint deployments to prevent malicious breaches.

Symantec and Carbon Black highlight the ongoing threat, noting that these vulnerabilities remain a significant risk for unpatched SharePoint systems, particularly those in Portuguese and Spanish-speaking regions. This pattern could indicate either opportunistic exploitation or a more targeted approach based on exposed systems.

To mitigate these risks, organizations are encouraged to update their security measures, patch vulnerabilities promptly, and remain vigilant against sophisticated threat actors like Warlock.

The Hacker News Tags:BYOVD, critical infrastructure, cyber attacks, Cybersecurity, Hacking, Microsoft, Portuguese-speaking countries, Ransomware, security tools, SharePoint, Spanish-speaking countries, Threat Actors, Vulnerabilities, Warlock, web shells

Post navigation

Previous Post: Microsoft Releases Critical Exchange Update for Security Flaw
Next Post: Addressing Cybersecurity in an Era of Connected Vehicles

Related Posts

Supply Chain Attacks Surge Amid New Malware Techniques Supply Chain Attacks Surge Amid New Malware Techniques The Hacker News
CISA Warns of Active Exploitation of Gogs Vulnerability Enabling Code Execution CISA Warns of Active Exploitation of Gogs Vulnerability Enabling Code Execution The Hacker News
Severe Figma MCP Vulnerability Lets Hackers Execute Code Remotely — Patch Now Severe Figma MCP Vulnerability Lets Hackers Execute Code Remotely — Patch Now The Hacker News
Critical Vulnerability in Cisco SD-WAN Manager Exploited Critical Vulnerability in Cisco SD-WAN Manager Exploited The Hacker News
Supply Chain Attack Exposes OpenAI Codex Tokens Supply Chain Attack Exposes OpenAI Codex Tokens The Hacker News
New Malware Campaign Uses Cloudflare Tunnels to Deliver RATs via Phishing Chains New Malware Campaign Uses Cloudflare Tunnels to Deliver RATs via Phishing Chains The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Addressing Cybersecurity in an Era of Connected Vehicles
  • Warlock Group Targets SharePoint Flaws for Ransomware Attacks
  • Microsoft Releases Critical Exchange Update for Security Flaw
  • MI5 Warns of China’s Influence on UK Academics
  • Doxx.net Secures $38 Million for AI Safety Platform

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Addressing Cybersecurity in an Era of Connected Vehicles
  • Warlock Group Targets SharePoint Flaws for Ransomware Attacks
  • Microsoft Releases Critical Exchange Update for Security Flaw
  • MI5 Warns of China’s Influence on UK Academics
  • Doxx.net Secures $38 Million for AI Safety Platform

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark