Warlock Ransomware SharePoint Attacks

Warlock ransomware SharePoint attacks have reached a water utility, a telecom provider, a regional government body and a university, according to Symantec and Carbon Black. The China-linked group still gets in through on-premises SharePoint, switches off endpoint protection on dozens of machines within about two hours, and then launches ransomware from a share that every domain controller replicates. Over the past two months it has focused on Portuguese- and Spanish-speaking countries across Europe, Africa and Latin America.
What Happened
The Warlock ransomware SharePoint attacks follow a fixed pattern. Symantec tracks the actor as Longlegs and attributes the development of Warlock to it; Microsoft followed the same activity as Storm-2603. The group appeared in June 2025 and became known a month later by exploiting the SharePoint zero-day chain called ToolShell (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, CVE-2025-53771). The new report says ToolShell and other SharePoint flaws remain a working way in more than a year later. It does not name which SharePoint vulnerabilities were used in the latest intrusions.
According to BleepingComputer’s account of the report, in one intrusion that began on July 22, the attackers dropped a web shell built to work across several SharePoint versions, did reconnaissance two days later, and installed Visual Studio Code Insiders as a service so they could reach the machines through its built-in tunneling. They used NetExec for Active Directory enumeration. On July 31 they deployed an EDR killer through a bring-your-own-vulnerable-driver technique, using the signed K7RKScan driver, which is vulnerable to CVE-2025-1055. It disabled protection on at least 40 hosts in about two hours. Warlock ran on at least 33 hosts almost as soon as protection went down, and the payload was staged in SYSVOL, the domain share that is replicated to every domain controller and can push a logon script or Group Policy object across the whole network at once.
Why It Matters
SharePoint was the entry point; the damage came from what happened after it. Writing a payload to SYSVOL and killing security tooling on 40 hosts in two hours points to domain-level rights before the ransomware ever started. That is a different problem from a missed patch: a patched farm whose ASP.NET machine keys were already stolen can be re-entered, which is why rotating them is part of the standard ToolShell clean-up. We tracked this pattern across the summer, from CVE-2026-45659, where Microsoft tied Storm-2603 and Warlock to active exploitation, through machine-key theft to the Swiss federal breach.
The reporting names no victim in Germany, Austria or Switzerland. The stack is familiar here, though: on-premises SharePoint, Active Directory and domain-wide logon scripts are standard in the Mittelstand, and water and telecom operators fall under NIS2 and KRITIS rules. Assessment: the technique transfers directly; only the language of the targets differs so far.
What You Should Do Now
- Confirm every on-premises SharePoint server (2016, 2019, Subscription Edition) has current security updates, including the fix for CVE-2026-65660, which CISA added to its Known Exploited Vulnerabilities catalog on September 25.
- Rotate the ASP.NET machine keys on all farm servers after patching and restart IIS. Patching alone does not remove a stolen key.
- Hunt on SharePoint servers for unexpected web shell files and for new accounts in the local Administrators group. Symantec’s indicator list reportedly includes a domain account named SPSEPRDSetup, chosen to look like a SharePoint setup account.
- Hunt across the domain for a code-insiders.exe service with the tunnel option, NetExec, loads of the K7RKScan driver, and new files in the SYSVOL scripts folder. Turn on the Microsoft vulnerable driver blocklist.
- Enable EDR tamper protection and alert when security services stop on more than one host at the same time. Forty hosts in two hours is detectable if someone is looking.
DIESEC Perspective
In the intrusion described, the decisive step was one that rarely gets watched: who can write to SYSVOL and Group Policy. Organizations that alert on those changes and limit domain admin logons to dedicated hosts turn a two-hour wave into an alarm.
Not sure whether your SharePoint farm was patched and its machine keys rotated, or whether your domain shows these traces? Contact DIESEC for a rapid SharePoint exposure review and compromise check.
Sources: Symantec and Carbon Black | BleepingComputer
Published: 2026-10-07 | Category: Ransomware & Extortion | ~5 min read

