A threat actor group, Warlock, believed to be linked to China, has been actively exploiting vulnerabilities in Microsoft SharePoint to launch attacks on organizations in countries where Portuguese and Spanish are spoken. The activity, identified by Symantec and Carbon Black, has targeted a variety of sectors, including critical infrastructure, government, and education.
Impact on Critical Sectors
In recent months, Warlock, also known as Gold Salem, Longlegs, and Storm-2603, has intensified its operations. Notably, it has attacked at least four organizations, as reported by Broadcom’s cybersecurity division. These attacks have affected two critical infrastructure operators, a regional government entity, and a university across Europe, Africa, and Latin America.
Warlock’s notoriety rose in 2025 due to its use of zero-day exploits in SharePoint, particularly with the ‘ToolShell’ flaws, to deploy ransomware. This year, they were implicated in the breach of SmarterTools by exploiting an unpatched SmarterMail instance. They also use legitimate tools like Velociraptor for command-and-control and the bring your own vulnerable driver (BYOVD) method to disable security software.
Tactics and Techniques
Warlock’s attack strategies involve exploiting multiple vulnerabilities in on-premises SharePoint Server setups. Once inside, they deploy web shells to target various SharePoint versions. The main goal is to collect ASP.NET machine keys, allowing them to forge a validly signed payload and gain remote code execution within the SharePoint environment.
The group employs several sophisticated techniques, such as DLL sideloading to introduce malicious code, downloading additional payloads from legitimate cloud services to avoid detection, and using vulnerable drivers to disable security tools. Additionally, they leverage ‘living-off-the-land’ techniques, such as using Microsoft Visual Studio Code’s tunnel feature for remote access.
Ongoing Threat and Response
By July 2026, Warlock continued exploiting SharePoint Server flaws to deploy web shells, enabling them to conduct network reconnaissance, execute arbitrary code, and distribute further payloads, including ransomware. Their attacks emphasize the necessity for patched and secure SharePoint deployments to prevent malicious breaches.
Symantec and Carbon Black highlight the ongoing threat, noting that these vulnerabilities remain a significant risk for unpatched SharePoint systems, particularly those in Portuguese and Spanish-speaking regions. This pattern could indicate either opportunistic exploitation or a more targeted approach based on exposed systems.
To mitigate these risks, organizations are encouraged to update their security measures, patch vulnerabilities promptly, and remain vigilant against sophisticated threat actors like Warlock.
