Warlock ransomware hits water, telecom via SharePoint flaws

Warlock ransomware hits water, telecom via SharePoint flaws

The group behind Warlock ransomware is still breaking into organizations through Microsoft SharePoint servers. Its recent victims include critical infrastructure operators, a regional government body and a university, according to a new report from Symantec.

Over the past two months, the operator has compromised at least four organizations in Portuguese- and Spanish-speaking countries. Symantec says the victims were a water utility, a telecommunications provider, a regional government body and a university.

Who is behind Warlock

Warlock is thought to be run by a China-based group that Symantec tracks as Longlegs. Other researchers call it Storm-2603. The group has been connected to operations known as CL-CRI-1040, CamoFei and ChamelGang.

The group first drew wide attention during last year's ToolShell campaign. ToolShell is the name given to two SharePoint vulnerabilities that the Chinese state-sponsored groups Linen Typhoon and Violet Typhoon exploited as zero-days at least two weeks before they were publicly disclosed. More than 400 SharePoint servers were compromised within weeks. Storm-2603's use of ToolShell stood out even among the heavy activity from advanced persistent threat (APT) groups at the time.

By October 2025, researchers had linked many Warlock ransomware attacks to ToolShell exploitation. Victims included a telecom company in the Middle East, government entities in Africa and South America, and a university in the US.

New SharePoint bugs in the toolkit

Symantec's latest findings show that SharePoint is still the group's preferred way in. Besides ToolShell, its arsenal may also include several recent flaws: CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, CVE-2026-58644, CVE-2026-50522 and CVE-2026-55040.

The intrusions usually follow the same pattern. The attackers exploit a SharePoint flaw, plant a webshell and steal ASP.NET machine keys. They then deploy a forced signed payload to achieve remote code execution (RCE).

Once inside, Storm-2603 uses DLL sideloading to run code in memory. It pulls additional payloads from legitimate file-sharing and storage services and drops a vulnerable driver to switch off security tools. For reconnaissance and command execution, it relies on living-off-the-land tools, meaning legitimate utilities already present on the system.

In one intrusion, the attackers used a tool to disable security software on at least 40 systems. They then ran Warlock on at least 33 of those machines.

Hiding in developer traffic

Symantec also observed the group abusing a feature of Visual Studio Code, Microsoft's popular code editor.

"The group has also been observed abusing Visual Studio Code's built-in tunnel feature, installing the code-insiders.exe binary as a service to establish covert remote network access that blends into traffic that typically originates from developer or administrator workstations," the researchers noted.

To push the ransomware across a network, the attackers stage the Warlock payload in the domain's SYSVOL share. SYSVOL is a shared folder in Windows Active Directory environments that is automatically replicated to every domain controller and can be read across the whole domain. That makes it a convenient launch point for encrypting many machines at once.

Symantec says the group's persistence points to a broader problem with unpatched servers.

"Longlegs' continued activity, more than a year after Warlock ransomware first came to prominence, shows that exploitation of ToolShell and other related SharePoint vulnerabilities remains a viable initial access route for attackers on SharePoint deployments that have not been patched or otherwise mitigated," the company said.

Our Take

The most telling detail in Symantec's report is not the list of new CVEs but the fact that ToolShell still works for these attackers more than a year later. This suggests that a meaningful number of on-premises SharePoint servers remain unpatched or unmitigated, even after one of the most widely publicized exploitation waves of 2025. For defenders, the lesson is uncomfortable but familiar: disclosure and patch availability do not close the window. That window is narrowing on the attacker side as vulnerability disclosures and exploitation speed up.

The victim list also matters. A water utility and a telecom provider are the kind of targets where disruption reaches far beyond the breached organization. Telecom networks in particular have been in the spotlight, with the Salt Typhoon intrusions prompting proposed telecom cyber rules in the US. A China-based group that blends state-linked tradecraft with ransomware adds another layer to that threat picture.

Organizations running SharePoint on-premises should check exposure to the CVEs named above, rotate ASP.NET machine keys after any suspected compromise and review SYSVOL for unexpected executables. Unexplained VS Code tunnel services are also worth hunting for. It is worth watching whether the group's victims spread beyond Portuguese- and Spanish-speaking countries, and whether other ransomware crews adopt the same SharePoint playbook.