Close Menu

    Subscribe to Updates

    Get the latest Tech news from SynapseFlow

    What's Hot

    macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor

    October 2, 2026

    Government Officials Order the Robot Cage Fights to Stop, Organizers Say

    October 2, 2026

    Gears of War: E-Day review: old-school action is a breath of fresh air in 2026

    October 2, 2026
    Facebook X (Twitter) Instagram
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    Facebook X (Twitter) Instagram YouTube
    synapseflow.co.uksynapseflow.co.uk
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    synapseflow.co.uksynapseflow.co.uk
    Home»Cybersecurity»Warlock Expands SharePoint Exploitation in Critical Infrastructure Attacks
    Warlock Expands SharePoint Exploitation in Critical Infrastructure Attacks
    Cybersecurity

    Warlock Expands SharePoint Exploitation in Critical Infrastructure Attacks

    The Tech GuyBy The Tech GuyOctober 2, 2026No Comments3 Mins Read0 Views
    Share
    Facebook Twitter LinkedIn Pinterest Email
    Advertisement


    The Warlock ransomware group continues to target SharePoint servers in attacks against critical infrastructure, government, and education entities, Symantec reports.

    Advertisement

    Warlock is believed to be operated by a China-based hacking group tracked as Longlegs and Storm-2603, which has been linked to malicious operations such as CL-CRI-1040, CamoFei, and ChamelGang.

    Last year, the Chinese state-sponsored groups Linen Typhoon and Violet Typhoon were seen exploiting two SharePoint vulnerabilities dubbed ToolShell as zero-days at least two weeks before public disclosure.

    Within weeks, more than 400 SharePoint servers were compromised, and Storm-2603’s exploitation of ToolShell stood out amid heavy APT activity.

    By October 2025, researchers uncovered numerous Warlock ransomware attacks that exploited ToolShell. Some of the group’s victims included a Middle East telecom firm, African and South American government entities, and a US university.

    According to a fresh Symantec report, Storm-2603 continues to favor the exploitation of SharePoint bugs in attacks. In addition to ToolShell, its arsenal may also include recent flaws such as CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, CVE-2026-58644, CVE-2026-50522, and CVE-2026-55040.

    Advertisement. Scroll to continue reading.

    Over the past two months, the Warlock operator has hit at least four victim organizations in Portuguese- and Spanish-speaking countries.

    “The victims included two critical infrastructure operators, a water utility and a telecommunications provider, along with a regional government body and a university,” Symantec reports.

    As part of one intrusion, the hacking group deployed a tool to disable the security software on at least 40 systems and then executed Warlock on at least 33 of them.

    The group’s exploitation of SharePoint flaws is typically followed by webshell deployment, ASP.NET machine key exfiltration, and the deployment of a forced signed payload for remote code execution (RCE).

    Storm-2603 relies on DLL sideloading for in-memory code execution, drops additional payloads from legitimate file-sharing and storage services and a vulnerable driver to disable security tools, and relies on living-off-the-land tools for reconnaissance and command execution.

    “The group has also been observed abusing Visual Studio Code’s built-in tunnel feature, installing the code-insiders.exe binary as a service to establish covert remote network access that blends into traffic that typically originates from developer or administrator workstations,” Symantec notes.

    Additionally, the threat actor stages the Warlock payload inside the domain’s SYSVOL share, which is automatically replicated to every domain controller and is readable domain-wide, to execute the file-encrypting ransomware at scale.

    “Longlegs’ continued activity, more than a year after Warlock ransomware first came to prominence, shows that exploitation of ToolShell and other related SharePoint vulnerabilities remains a viable initial access route for attackers on SharePoint deployments that have not been patched or otherwise mitigated,” Symantec notes.

    Related: Russian APT Star Blizzard Uses ‘RedFlick’ Infection Chain in Recent Attacks

    Related: Hackers Use ChatGPT Custom GPTs in ClickFix Attacks

    Related: Daemon Tools Hackers’ NeedyMantis Malware Dissected by Microsoft

    Related: SmarterTools Hit by Ransomware via Vulnerability in Its Own Product

    Advertisement
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    The Tech Guy
    • Website

    Related Posts

    macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor

    October 2, 2026

    In Other News: $15K iCloud Spoofing Bugs, AI Policy Experts Phished, Adblocker Spies on AI Chats

    October 2, 2026

    Osavul Lands $10 Million to Spot Hostile Intent Across Cyber, Physical Domains

    October 2, 2026

    Zero Trust Creator Says Model Holds Firm Against AI-Assisted Attacks

    October 1, 2026

    Enterprises Struggle to Prepare for AI and Quantum Threats, PwC Says

    October 1, 2026

    Treasury Blacklists Most-Wanted ATM Malware Developer and His Network

    October 1, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    You don’t need a NAS to self-host — I proved it with hardware from my closet

    June 7, 2026392 Views

    Spotify is giving one of its best playlists a big visual upgrade to give subscribers ‘a closer connection’ to its New Music Friday curators — and I think it could be the update it’s always needed

    June 12, 2026211 Views

    The iPad Air brand makes no sense – it needs a rethink

    October 12, 202517 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Advertisement
    About Us
    About Us

    SynapseFlow brings you the latest updates in Technology, AI, and Gadgets from innovations and reviews to future trends. Stay smart, stay updated with the tech world every day!

    Our Picks

    macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor

    October 2, 2026

    Government Officials Order the Robot Cage Fights to Stop, Organizers Say

    October 2, 2026

    Gears of War: E-Day review: old-school action is a breath of fresh air in 2026

    October 2, 2026
    categories
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    Facebook X (Twitter) Instagram Pinterest YouTube Dribbble
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    © 2026 SynapseFlow All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.