HomeMalware & ThreatsWarlock Exploits SharePoint Vulnerabilities to Bypass Security and Launch Ransomware Attacks

Warlock Exploits SharePoint Vulnerabilities to Bypass Security and Launch Ransomware Attacks

Published on

spot_img

The cybersecurity landscape continues to face challenges from a sophisticated threat actor suspected to be linked to China, known as Warlock. Recent reports indicate that this group is actively targeting vulnerabilities in Microsoft SharePoint, utilizing both older and newly discovered weaknesses. Their operations have primarily focused on organizations situated in Portuguese- and Spanish-speaking regions, spanning multiple continents such as Europe, Africa, and Latin America.

The Symantec and Carbon Black Threat Hunter Team have been monitoring this campaign, identifying attacks against a range of crucial infrastructures, including government agencies and educational institutions. Notably, in just the last two months, the Warlock group has been implicated in assaults on at least four distinct entities. These attacks included two critical infrastructure operators: a water utility provider and a telecommunications company, along with a regional government body and a university.

Warlock, which operates under various aliases such as Gold Salem, Longlegs, and Storm-2603, gained notoriety in mid-2025, primarily due to its exploitation of “ToolShell” SharePoint vulnerabilities. These flaws have allowed the organization to deploy ransomware effectively on targeted systems. Earlier this year, they were linked to an incident involving SmarterTools, where an unpatched SmarterMail system was exploited to gain unauthorized access.

Warlock’s methods have shown a reliance on legitimate tools, including Velociraptor, to facilitate command and control operations. They have also employed the Bring Your Own Vulnerable Driver (BYOVD) technique, which involves using an exploitable driver to circumvent security protocols on compromised systems.

According to Symantec, the Warlock group shares characteristics with older activity clusters, including CL-CRI-1040, CamoFei, and ChamelGang. This overlap suggests a continuation of methodologies that have been proven successful for cybercriminals in the past. For instance, during an intrusion against a critical infrastructure operator, it was reported that the attackers utilized a tool designed to disable security software across at least 40 systems within a mere two hours. Following this, Warlock deployed its ransomware to 33 hosts by placing it in the domain’s SYSVOL share, thus exploiting domain replication to spread the malicious code efficiently.

The attacks attributed to Warlock have capitalized on various vulnerabilities associated with on-premises installations of Microsoft SharePoint Server. Once access is secured, these threat actors deploy web shells, designed to target multiple versions of SharePoint. The ultimate objective of these web shells is to harvest the ASP.NET machine keys from the SharePoint farm. These keys are then manipulated to create a validly signed payload, granting the attackers remote code execution capabilities within the SharePoint application pool.

Several other techniques have also been observed during their operations, including:

  • DLL sideloading, which allows malicious code to be injected into memory.
  • The download of follow-on payloads from legitimate cloud storage services, such as catbox[.]moe and wasabisys[.]com, enabling them to evade detection.
  • Exploiting drivers deemed legitimate but vulnerable, such as K7RKScan.sys (CVE-2025-1055), to perform a BYOVD attack aimed at disabling security measures.
  • Utilizing living-off-the-land (LotL) tools for reconnaissance and command execution on compromised hosts. This strategy includes the exploitation of Microsoft Visual Studio Code’s built-in tunnel feature to enhance remote access to infected systems.
  • Staging ransomware payloads within the compromised domain’s SYSVOL share, facilitating larger-scale deployments.

Most strikingly, as of July 22, 2026, the threat actors have reportedly resumed exploiting SharePoint Server flaws to drop web shells, conduct extensive internal discovery operations, and obtain arbitrary code execution in the SharePoint application pool. They have been observed deploying additional malicious payloads, deepening their penetration into networks, establishing secure tunnels via Visual Studio Code, disabling security software, and ultimately deploying ransomware binaries.

The continued activity of Warlock, over a year since its emergence, highlights the persistent risks associated with the exploitation of ToolShell and other SharePoint vulnerabilities. This situation serves as a reminder to organizations to ensure that their SharePoint deployments are adequately patched and safeguarded against such attacks.

Furthermore, the recent targeting of predominantly Portuguese- and Spanish-speaking countries may indicate either an opportunistic approach predicated on vulnerable SharePoint servers or a more orchestrated effort to specifically engage these regions. The implications of these ongoing threats underscore the necessity for heightened vigilance and proactive cybersecurity measures across the globe.

Source link

Latest articles

Citrix NetScaler Appliances Experience Continuous Reboots Following 0-Day Security Update

Repeated Crashes and Reboots Faced by Citrix NetScaler Appliances Following Vulnerability Patches In a pressing...

Microsoft Activates Default Windows Settings Backup

Microsoft Activates Automatic Settings Backup for Enterprise Devices In a significant update for enterprise users,...

AWS AI Agent Vulnerabilities Allow Attackers to Bypass Authentication and Steal Credentials

AWS (Amazon Web Services) has recently announced critical security fixes addressing vulnerabilities identified within...

Shadow AI Governance Creates Security Gaps

In recent years, the rise of generative artificial intelligence (AI) tools has led employees...

More like this

Citrix NetScaler Appliances Experience Continuous Reboots Following 0-Day Security Update

Repeated Crashes and Reboots Faced by Citrix NetScaler Appliances Following Vulnerability Patches In a pressing...

Microsoft Activates Default Windows Settings Backup

Microsoft Activates Automatic Settings Backup for Enterprise Devices In a significant update for enterprise users,...

AWS AI Agent Vulnerabilities Allow Attackers to Bypass Authentication and Steal Credentials

AWS (Amazon Web Services) has recently announced critical security fixes addressing vulnerabilities identified within...