[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2sZGa_99LGnx00QafvD5o6BE2MHQ3njkQdvurpLRYms":3},{"article":4,"iocs":55},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":32,"category":33,"article_tags":37},"a9fe9fba-edb9-4d5c-88ff-26006f9f2a6d","Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware","warlock-exploits-sharepoint-flaws-to-disable-security-tools-and-deploy-ransomwar-d5d7c3","The suspected China-linked threat actor known as Warlock is still continuing to weaponize Microsoft SharePoint vulnerabilities, likely both old and new, in attacks targeting organizations in Portuguese- and Spanish-speaking countries. The activity, observed by the Symantec and Carbon Black Threat Hunter Team, has hit critical infrastructure, government, and education organizations. \"In the","The China-linked threat actor Warlock continues to exploit Microsoft SharePoint vulnerabilities to target organizations in Portuguese- and Spanish-speaking countries. The group, also known as Gold Salem and Longlegs, has recently targeted critical infrastructure, government, and education sectors, deploying ransomware after disabling security tools using legitimate drivers and LotL techniques.","Warlock exploits SharePoint flaws to deploy ransomware and disable security tools.","Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware Ravie LakshmananOct 03, 2026Vulnerability \u002F Critical Infrastructure The suspected China-linked threat actor known as Warlock is still continuing to weaponize Microsoft SharePoint vulnerabilities, likely both old and new, in attacks targeting organizations in Portuguese- and Spanish-speaking countries. The activity, observed by the Symantec and Carbon Black Threat Hunter Team, has hit critical infrastructure, government, and education organizations. \"In the past two months, Longlegs has attacked at least four organizations, including two critical infrastructure operators (a water utility and a telecommunications provider), a regional government body, and a university,\" the Broadcom-owned cybersecurity unit said. \"Victims were in Portuguese- and Spanish-speaking countries, spanning Europe, Africa, and Latin America.\" Warlock, also tracked as Gold Salem, Longlegs, and Storm-2603, gained prominence in mid-2025 in connection with the zero-day exploitation of the \"ToolShell\" SharePoint flaws to deploy ransomware on targeted systems. Earlier this year, the group was linked to the compromise of SmarterTools by exploiting an unpatched SmarterMail instance. It has also relied on legitimate tools like Velociraptor for command-and-control (C2) and the bring your own vulnerable driver (BYOVD) technique to disarm security software running on a compromised host. According to Symantec, Warlock shares overlaps with older activity clusters known as CL-CRI-1040, CamoFei, and ChamelGang. \"In one intrusion against a critical infrastructure operator, the attackers pushed a tool designed to disable security software to at least 40 hosts within about two hours, then deployed Warlock on at least 33 hosts by staging it in the domain's SYSVOL share, where ordinary domain replication delivered it to machines,\" the researchers said. Attacks mounted by Warlock have leveraged multiple vulnerabilities in on-premises Microsoft SharePoint Server deployments. Upon successfully finding a way in, the threat actors have been found to drop web shells that can target multiple versions of SharePoint. The end goal of the web shell is to collect the SharePoint farm's ASP.NET machine keys, which are then abused to forge a validly signed payload and achieve remote code execution inside the SharePoint application pool. Some of the other observed tactics are listed below - Using DLL sideloading to load malicious code into memory. Downloading follow-on payloads from legitimate cloud file-sharing and storage services such as catbox[.]moe and wasabisys[.]com to fly under the radar. Abusing a legitimate-but-vulnerable driver K7RKScan.sys (CVE-2025-1055) as part of a BYOVD attack to disable security software. The same driver was previously exploited by DragonForce ransomware actors. Using living-off-the-land (LotL) tooling to perform reconnaissance and run commands on the compromised hosts. This includes the abuse of Microsoft Visual Studio Code's built-in tunnel feature to facilitate remote connections to infected systems. Staging payloads inside the compromised domain's SYSVOL share to deploy ransomware at scale. As recently as July 22, 2026, the threat actors are said to have exploited SharePoint Server flaws to drop a web shell, conduct discovery, obtain arbitrary code execution inside the SharePoint application pool, deploy additional payloads, burrow deeper into the network, establish VS Code tunnels, terminate security software, and ultimately deploy the ransomware binary. \"Longlegs' continued activity, more than a year after Warlock ransomware first came to prominence, shows that exploitation of ToolShell and other related-SharePoint vulnerabilities remains a viable initial access route for attackers SharePoint deployments that have not been patched or otherwise mitigated,\" Symantec and Carbon Black said. \"The apparent recent focus on Portuguese- and Spanish-speaking countries suggests either an opportunistic targeting pattern driven by exposed, vulnerable SharePoint servers, or a more deliberate tasking.\" Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  critical infrastructure, Microsoft, ransomware, Vulnerability, Web Security ⚡ Top Stories This Week Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild Cloudflare Fixes Flaw That Let One Container Read Another Customer's Leftover Disk Data Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions ThreatsDay: AI Search Poisoning, AI Coding Tool Leaking Repos, One-Click Code Execution and 13 More Stories Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content OpenAI Agent Bypassed Australian Medicare Portal Controls to Access Non-Public Files A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers Researcher Drops BigDiskBuster Zero-Day PoC That Blocks Microsoft Defender Updates New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups New Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host Memory SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access Beyond ISO 27001: Building a Risk Program That Can Keep Up With AI Secrets Sprawl Is an Identity Problem That AI Just Made Impossible to Ignore ⭐ Featured Resources Validation Summit ’26: See How Pen Testing, Exposure Validation and BAS Work Together Red Teams: Learn How Attack Path Chaining Changes Automated Security Testing Turn Threat Intelligence Into Verified Risk With Threat-Led Penetration Testing Deploy Browser Security Monitoring in Minutes With a Single Header","https:\u002F\u002Fthehackernews.com\u002F2026\u002F10\u002Fwarlock-exploits-sharepoint-flaws-to.html","https:\u002F\u002Fblogger.googleusercontent.com\u002Fimg\u002Fb\u002FR29vZ2xl\u002FAVvXsEjCZSaqs29yWFrct8zgOikM9e4CS0xuAXppzGJ1tskKpKC2gbGuITsYlHYNcnXDMvrFpPuAVS_ZlyEF8Obp7Mgw7CUXe4UsKP3pNEvZWNfszKQVxogslYpoWBZG-QQbEvmS6SDcbgVtXiFFGIEjreD_HSkCYZTfcwL1Rt90qDbbPj946SbMX0FR5CEKRt_H\u002Fs1600\u002Fsharepoint-ransomware.jpg","2026-10-03T14:36:33+00:00","2026-10-03T16:00:11.631976+00:00",9,[18,21,23,25,27,29],{"name":19,"type":20},"Warlock","threat_actor",{"name":22,"type":20},"Gold Salem",{"name":24,"type":20},"Longlegs",{"name":26,"type":20},"Storm-2603",{"name":28,"type":20},"DragonForce",{"name":30,"type":31},"Microsoft SharePoint","product","6cbdd207-aaa1-4176-9534-e156b125e917",{"id":32,"icon":34,"name":35,"slug":36},null,"Nation-state","nation-state",[38,40,45,50],{"category":39},{"id":32,"icon":34,"name":35,"slug":36},{"category":41},{"id":42,"icon":34,"name":43,"slug":44},"7d8b5ab8-ea0b-4ced-ae97-ec251b86993a","Ransomware","ransomware",{"category":46},{"id":47,"icon":34,"name":48,"slug":49},"80544778-fabb-4dcd-aa35-17492e5dcf4f","Vulnerabilities","vulnerabilities",{"category":51},{"id":52,"icon":34,"name":53,"slug":54},"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5","Malware","malware",[56],{"type":57,"value":58,"context":59},"cve","CVE-2025-1055","Vulnerable driver K7RKScan.sys used to disable security software"]