Warlock Hackers Exploit SharePoint Bugs to Kill Security Tools and Deploy Ransomware
A suspected China-linked threat group called Warlock (also known as Gold Salem, Longlegs, or Storm-2603) is continuing to exploit vulnerabilities in on-premises Microsoft SharePoint Server deployments, targeting organisations in Portuguese and Spanish-speaking countries across Europe, Africa, and Latin America. Researchers at Symantec and Carbon Black report that at least four organisations have been hit in the past two months, including a water utility, a telecommunications provider, a regional government body, and a university.
Once inside a network, the attackers drop web shells designed to work across multiple SharePoint versions. These web shells are used to steal cryptographic keys from the SharePoint server, allowing the attackers to forge trusted payloads and run malicious code with high privileges. In one incident against a critical infrastructure operator, Warlock pushed a tool to disable security software on around 40 machines within two hours, then spread ransomware to at least 33 hosts by hiding it in a shared network folder used for routine domain updates.
Warlock first gained attention in mid-2025 after exploiting so-called 'ToolShell' SharePoint flaws as zero-days to deploy ransomware. The group has also been linked to a separate compromise involving an unpatched email server product, and is known to use legitimate remote administration tools alongside techniques that abuse vulnerable drivers to turn off endpoint security protections.