Structured data rendered for: graph
Back to Blog

Warlock ransomware is turning old SharePoint exposure into critical infrastructure outages

Published
Updated
6 min read
Warlock ransomware is turning old SharePoint exposure into critical infrastructure outages

Warlock ransomware is turning old SharePoint exposure into critical infrastructure outages

Warlock ransomware is back in the spotlight because the operators behind it are still finding value in Microsoft SharePoint servers that were never fully patched or mitigated. Symantec and Carbon Black researchers say the China-nexus actor they track as Longlegs, also known as Storm-2603, recently attacked at least four organizations across Portuguese- and Spanish-speaking regions in Europe, Africa, and Latin America.

The victim set matters. It included a water utility, a telecommunications provider, a regional government body, and a university. That makes this more than another ransomware deployment story. It is a reminder that collaboration platforms sitting at the edge of a Windows domain can become the shortest route from an exposed web server to service disruption.

What happened

The Warlock operators continue to favor on-premises SharePoint Server as an initial access path. The campaign builds on the ToolShell exploitation pattern that became public in 2025, involving CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771. Researchers also warned that newer SharePoint issues may be part of the actor's current arsenal.

After access is gained, the actor drops a web shell into SharePoint paths that can work across multiple SharePoint versions. The next move is especially dangerous: harvesting ASP.NET machine keys from the SharePoint farm, then using them to forge a valid signed payload that enables remote code execution inside the SharePoint application pool.

That turns a web-facing vulnerability into a domain compromise problem.

Why this campaign stands out

In one investigated intrusion, malicious activity began on July 22, 2026, when a web shell was installed on a SharePoint server. Two days later, the actor resumed with reconnaissance commands, cleanup of staging files, DLL sideloading, and lateral movement preparation.

The campaign then escalated quickly. Symantec reported that the attackers pushed an AV and EDR killing tool to at least 40 hosts in about two hours. Warlock ransomware then appeared on at least 33 hosts almost immediately after protections were disabled.

The defense evasion method is familiar but still effective. The group abused a signed vulnerable K7RKScan driver tracked as CVE-2025-1055, a bring-your-own-vulnerable-driver technique that lets attackers terminate protected security processes at the kernel level. That is the moment many endpoint programs lose visibility exactly when the network needs it most.

SharePoint was only the doorway

The campaign did not stop at a web shell. Longlegs used living-off-the-land tooling for reconnaissance and command execution, including domain trust enumeration, local administrator group changes, and NetExec activity for Active Directory enumeration, credential spraying, and remote command execution.

Researchers also observed abuse of Visual Studio Code Insiders' built-in tunneling capability. The attacker installed code-insiders.exe as a service, creating remote access that can blend into developer or administrator traffic because the binary is signed by Microsoft and the tunnel uses Microsoft infrastructure.

For defenders, this is the uncomfortable part: the activity can look like ordinary admin tooling unless it is tied back to the original intrusion path and the wrong machine doing the wrong thing at the wrong time.

SYSVOL made the blast radius bigger

The final ransomware deployment used a domain-wide distribution trick. The attackers staged Warlock payloads in the domain's SYSVOL share, a location replicated across domain controllers and readable across the domain.

That placement lets ransomware spread through normal domain replication and execution paths rather than being copied host by host. In the investigated intrusion, Warlock binaries named run.exe and rune.exe, plus a ransom note titled how to restore your files.txt, were recorded on at least 33 systems.

This is why initial SharePoint containment is not enough. Once the actor reaches Active Directory and SYSVOL, the incident shifts from web server remediation to full domain response.

Why defenders should care now

The key lesson is not that SharePoint can be exploited. Defenders already know that. The lesson is that old exposure remains operationally valuable to ransomware crews long after emergency patch windows close.

Warlock first became widely known in 2025 through SharePoint exploitation. More than a year later, the same strategic access pattern is still working against organizations that operate essential services. A water utility or telecom provider does not need a novel zero-day to lose availability; an internet-facing collaboration server with incomplete remediation can be enough.

Immediate response priorities

Organizations running on-premises SharePoint should treat this campaign as a reason to validate remediation, not just confirm that patches were once installed.

Start with exposure:

  • Inventory all internet-facing and partner-facing SharePoint servers.
  • Confirm that ToolShell-related updates and later SharePoint security updates are actually applied.
  • Verify mitigation status for servers that could not be patched immediately.
  • Review any SharePoint servers that were historically exposed during 2025 and 2026, even if they are patched now.

Then hunt for post-exploitation:

  • Unexpected ASPX files or web shells under SharePoint LAYOUTS paths.
  • Evidence of ASP.NET machine key access or unusual SharePoint worker process child activity.
  • PowerShell loading .NET workflow assemblies or executing encoded commands from SharePoint hosts.
  • msiexec downloading packages from public file hosting services.
  • VS Code Insiders installed as a service on servers where it has no business purpose.
  • NetExec or CrackMapExec-like activity from SharePoint or adjacent hosts.
  • Suspicious use of SYSVOL script paths to stage executables.
  • AV or EDR process termination followed by rapid ransomware execution.

Teams should also review network segmentation around SharePoint. If a compromised SharePoint server can directly reach domain controllers, administrative shares, broad server ranges, and security tooling infrastructure, the environment is giving attackers a short path to scale.

Detection ideas

A practical first hunt is to connect SharePoint process ancestry to remote tooling and domain enumeration.

index=windows
(process_name=w3wp.exe OR parent_process_name=w3wp.exe OR process_name=powershell.exe OR process_name=cmd.exe)
("layouts" OR "__VIEWSTATE" OR "System.Workflow.ComponentModel" OR "nltest" OR "net localgroup administrators" OR "code-insiders.exe" OR "msiexec")
| stats min(_time) as firstSeen max(_time) as lastSeen values(command_line) as commands by host, user, process_name, parent_process_name

For SYSVOL staging:

index=windows
("SYSVOL" AND ("run.exe" OR "rune.exe" OR "how to restore your files.txt"))
| stats count min(_time) as firstSeen max(_time) as lastSeen values(parent_process_name) as parents values(command_line) as commands by host, user

For vulnerable-driver abuse:

index=edr OR index=windows
("K7RKScan" OR "CVE-2025-1055" OR "a.exe" OR "protected process" OR "kernel driver")
| stats count min(_time) as firstSeen max(_time) as lastSeen values(file_hash) as hashes values(command_line) as commands by host, user, process_name

Strategic takeaway

Warlock shows why patching has to be paired with exposure review, compromise assessment, and domain-level containment planning. A SharePoint patch can close the front door, but it does not prove the environment was not already entered.

For security teams, the right posture is simple: confirm SharePoint is patched, hunt for evidence that it was abused before remediation, restrict what SharePoint servers can reach, and make sure SYSVOL cannot become a ransomware distribution lane without triggering alarms.

The organizations most at risk are not necessarily the ones with the newest exploit in front of them. They are the ones where last year's emergency became this year's unfinished cleanup.

References

  1. https://www.security.com/threat-intelligence/warlock-ransomware-critical-infrastructure
  2. https://www.bleepingcomputer.com/news/security/warlock-ransomware-breach-sharepoint-in-water-telecom-operator-attacks/
  3. https://www.securityweek.com/warlock-expands-sharepoint-exploitation-in-critical-infrastructure-attacks/

FAQ

How to cite

Lucas Oliveira. Warlock ransomware is turning old SharePoint exposure into critical infrastructure outages. 3 Oct 2026. Invaders Cybersecurity. https://invaders.ie/resources/blog/cybercrime/warlock-ransomware-sharepoint-critical-infrastructure.

Subscribe via RSS.

Written by

Lucas Oliveira

Research

A DevOps engineer and cybersecurity enthusiast with a passion for uncovering the latest in zero-day exploits, automation, and emerging tech. I write to share real-world insights from the trenches of IT and security, aiming to make complex topics more accessible and actionable. Whether I’m building tools, tracking threat actors, or experimenting with AI workflows, I’m always exploring new ways to stay one step ahead in today’s fast-moving digital landscape.