Warlock Ransomware Continues Exploiting Older SharePoint Vulnerabilities to Target Critical Infrastructure Worldwide

Views: 41 views

547/69 Tuesday, October 6, 2026

The threat group behind Warlock ransomware, also known as Longlegs or Storm-2603, has reportedly continued exploiting the Microsoft SharePoint ToolShell vulnerability chain, first disclosed in mid-2025, as an initial access vector. Over the past two months, the group has attacked at least four organizations, including a water utility, a telecommunications provider, a regional government agency, and a university across Portuguese- and Spanish-speaking regions in Europe, Africa, and Latin America. Warlock has also previously targeted organizations in the United States, Brazil, India, Russia, Taiwan, and Japan. Researchers therefore assess that the group may be scanning for unpatched servers, selecting victims opportunistically, or targeting organizations based on a predefined list.

Analysis of the attacks found that the threat actors initially compromised systems by placing malicious scripts in SharePoint directories to steal encryption keys and execute malicious commands. They then downloaded malware-hosting files through public file-sharing services to make network activity appear more like legitimate traffic. The attackers also used Bring Your Own Vulnerable Driver (BYOVD) techniques to disable antivirus and Endpoint Detection and Response (EDR) tools, while abusing functionality in software development tools for remote system control and creating unauthorized administrator accounts to expand access. In a recent incident, the attackers were able to disable security defenses and distribute ransomware through the domain’s SYSVOL synchronization mechanism to dozens of computers within only a few hours.

To reduce the risk of this threat, network administrators and organizations still operating on-premises Microsoft SharePoint environments should immediately review their systems and apply all current security updates. Organizations can also refer to mitigation guidance issued by CISA in July 2026. In addition, administrators should closely monitor for suspicious creation of privileged or administrator accounts, investigate unusual remote access activity, and restrict access to centrally shared domain resources to prevent attackers from using them as a rapid malware distribution channel across the network.

Source: https://securityaffairs.com/200304/malware/warlock-ransomware-still-exploits-year-old-sharepoint-flaws-to-hit-critical-infrastructure.html