Warlock Ransomware Exploits ToolShell SharePoint Vulnerabilities
First seen 2 Dec 2025, 18:33 UTC
•
•100% similarity
•23
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
Warlock ransomware has been deployed through vulnerabilities in ToolShell SharePoint. Organizations using affected SharePoint versions are at risk, as the ransomware exploits chained vulnerabilities to gain access. Technical details indicate that the attack vector relies on specific weaknesses within the SharePoint infrastructure.
ThreatCluster AI