The cybersecurity landscape continues to face challenges from a sophisticated threat actor suspected to be linked to China, known as Warlock. Recent reports indicate that this group is actively targeting vulnerabilities in Microsoft SharePoint, utilizing both older and newly discovered weaknesses. Their operations have primarily focused on organizations situated in Portuguese- and Spanish-speaking regions, spanning multiple continents such as Europe, Africa, and Latin America.
The Symantec and Carbon Black Threat Hunter Team have been monitoring this campaign, identifying attacks against a range of crucial infrastructures, including government agencies and educational institutions. Notably, in just the last two months, the Warlock group has been implicated in assaults on at least four distinct entities. These attacks included two critical infrastructure operators: a water utility provider and a telecommunications company, along with a regional government body and a university.
Warlock, which operates under various aliases such as Gold Salem, Longlegs, and Storm-2603, gained notoriety in mid-2025, primarily due to its exploitation of “ToolShell” SharePoint vulnerabilities. These flaws have allowed the organization to deploy ransomware effectively on targeted systems. Earlier this year, they were linked to an incident involving SmarterTools, where an unpatched SmarterMail system was exploited to gain unauthorized access.
Warlock’s methods have shown a reliance on legitimate tools, including Velociraptor, to facilitate command and control operations. They have also employed the Bring Your Own Vulnerable Driver (BYOVD) technique, which involves using an exploitable driver to circumvent security protocols on compromised systems.
According to Symantec, the Warlock group shares characteristics with older activity clusters, including CL-CRI-1040, CamoFei, and ChamelGang. This overlap suggests a continuation of methodologies that have been proven successful for cybercriminals in the past. For instance, during an intrusion against a critical infrastructure operator, it was reported that the attackers utilized a tool designed to disable security software across at least 40 systems within a mere two hours. Following this, Warlock deployed its ransomware to 33 hosts by placing it in the domain’s SYSVOL share, thus exploiting domain replication to spread the malicious code efficiently.
The attacks attributed to Warlock have capitalized on various vulnerabilities associated with on-premises installations of Microsoft SharePoint Server. Once access is secured, these threat actors deploy web shells, designed to target multiple versions of SharePoint. The ultimate objective of these web shells is to harvest the ASP.NET machine keys from the SharePoint farm. These keys are then manipulated to create a validly signed payload, granting the attackers remote code execution capabilities within the SharePoint application pool.
Several other techniques have also been observed during their operations, including:
- DLL sideloading, which allows malicious code to be injected into memory.
- The download of follow-on payloads from legitimate cloud storage services, such as catbox[.]moe and wasabisys[.]com, enabling them to evade detection.
- Exploiting drivers deemed legitimate but vulnerable, such as K7RKScan.sys (CVE-2025-1055), to perform a BYOVD attack aimed at disabling security measures.
- Utilizing living-off-the-land (LotL) tools for reconnaissance and command execution on compromised hosts. This strategy includes the exploitation of Microsoft Visual Studio Code’s built-in tunnel feature to enhance remote access to infected systems.
- Staging ransomware payloads within the compromised domain’s SYSVOL share, facilitating larger-scale deployments.
Most strikingly, as of July 22, 2026, the threat actors have reportedly resumed exploiting SharePoint Server flaws to drop web shells, conduct extensive internal discovery operations, and obtain arbitrary code execution in the SharePoint application pool. They have been observed deploying additional malicious payloads, deepening their penetration into networks, establishing secure tunnels via Visual Studio Code, disabling security software, and ultimately deploying ransomware binaries.
The continued activity of Warlock, over a year since its emergence, highlights the persistent risks associated with the exploitation of ToolShell and other SharePoint vulnerabilities. This situation serves as a reminder to organizations to ensure that their SharePoint deployments are adequately patched and safeguarded against such attacks.
Furthermore, the recent targeting of predominantly Portuguese- and Spanish-speaking countries may indicate either an opportunistic approach predicated on vulnerable SharePoint servers or a more orchestrated effort to specifically engage these regions. The implications of these ongoing threats underscore the necessity for heightened vigilance and proactive cybersecurity measures across the globe.
