Skip to content
Warlock Expands SharePoint Exploitation in Critical Infrastructure Attacks

Warlock Expands SharePoint Exploitation in Critical Infrastructure Attacks

Securityweek • October 2, 2026

The Warlock ransomware group continues to target SharePoint servers in attacks against critical infrastructure, government, and education entities, Symantec reports.

Warlock is believed to be operated by a China-based hacking group tracked as Longlegs and Storm-2603, which has been linked to malicious operations such as CL-CRI-1040, CamoFei, and ChamelGang.

Last year, the Chinese state- groups Linen Typhoon and Violet Typhoon were seen exploiting two SharePoint vulnerabilities dubbed ToolShell as zero-days at least two weeks before public disclosure .

Within weeks, more than 400 SharePoint servers were compromised, and Storm-2603’s exploitation of ToolShell stood out amid heavy APT activity.

According to a fresh Symantec report , Storm-2603 continues to favor the exploitation of SharePoint bugs in attacks. In addition to ToolShell, its arsenal may also include recent flaws such as CVE-2026-32201, CVE-2026-45659, CVE-2026-56164 , CVE-2026-58644 , CVE-2026-50522 , and CVE-2026-55040 .

Over the past two months, the Warlock operator has hit at least four victim organizations in Portuguese- and Spanish-speaking countries.

“The victims included two critical infrastructure operators, a water utility and a telecommunications provider, along with a regional government body and a university,” Symantec reports.

As part of one intrusion, the hacking group deployed a tool to disable the security software on at least 40 systems and then executed Warlock on at least 33 of them.

The group’s exploitation of SharePoint flaws is typically followed by webshell deployment, ASP.NET machine key exfiltration, and the deployment of a forced signed payload for remote code execution (RCE).

Storm-2603 relies on DLL sideloading for in-memory code execution, drops additional payloads from legitimate file-sharing and storage services and a vulnerable driver to disable security tools, and relies on living-off-the-land tools for reconnaissance and command execution.

“The group has also been observed abusing Visual Studio Code’s built-in tunnel feature, installing the code-insiders.exe binary as a service to establish covert remote network access that blends into traffic that typically originates from developer or administrator workstations,” Symantec notes.

Additionally, the threat actor stages the Warlock payload inside the domain’s SYSVOL , which is automatically replicated to every domain controller and is readable domain-wide, to execute the file-encrypting ransomware at scale.

“Longlegs’ continued activity, more than a year after Warlock ransomware first came to prominence, shows that exploitation of ToolShell and other related SharePoint vulnerabilities remains a viable initial access route for attackers on SharePoint deployments that have not been patched or otherwise mitigated,” Symantec notes.

Related: Russian APT Star Blizzard Uses ‘RedFlick’ Infection Chain in Recent Attacks

Related: Hackers Use ChatGPT Custom GPTs in ClickFix Attacks

Related: Daemon Tools Hackers’ NeedyMantis Malware Dissected by Microsoft

Related: SmarterTools Hit by Ransomware via Vulnerability in Its Own Product

Exploited Fortinet FortiMail Zero-Day Calls for Urgent Action

CVE-2026-104286 is a critical-severity path traversal vulnerability that could allow attackers to write arbitrary files to the system.

Police Shut Down KillSec Ransomware, Identify Alleged Teen Leader

Police took control of KillSec’s leak site and secured at least 110 terabytes of data stolen from victims.

Zimbra Vulnerability Exploited in the Wild Prior to Public Disclosure

Under certain conditions, CVE-2026-73570 can be exploited via specially crafted emails without user interaction.

Artificial Intelligence

Zammad Zero-Days Exploited in AI-Powered DIVD Hack

The flaws were chained to hijack sessions, achieve remote code execution, and elevate privileges to root.

Cisco Patches Exploited Catalyst SD-WAN Zero-Day Vulnerability

The flaw could allow remote, unauthenticated attackers to access vulnerable appliances with administrative privileges.

Government, Finance Orgs Targeted in Weeks-Long NetScaler Zero-Day Attacks

Several security firms have confirmed seeing exploitation of the NetScaler vulnerabilities CVE-2026-88771 and CVE-2026-88772.

Daemon Tools Hackers’ NeedyMantis Malware Dissected by Microsoft

The malware framework uses a modular architecture and a custom executable file format for long-term persistence.

Apple Patches Zero-Day Linked to ‘Extremely Sophisticated Attack’

Apple released iOS and macOS updates to patch a zero-day vulnerability (CVE-2026-86950) reported by Meta’s product security team.