Published on October 4, 2026

Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware


Severity

Medium

Detail

A China-linked threat actor known as Warlock, also tracked as Gold Salem, Longlegs, and Storm-2603, continues to exploit vulnerabilities in on-premises Microsoft SharePoint Server environments. Recent attacks have targeted critical infrastructure, government, and education organizations across Portuguese- and Spanish-speaking countries in Europe, Africa, and Latin America.

The attackers have been observed exploiting SharePoint vulnerabilities to gain initial access and deploy web shells. The web shells are then used to obtain ASP.NET machine keys, which can be abused to forge validly signed payloads and achieve remote code execution within the SharePoint application pool.

How?

After compromising SharePoint, the attackers deploy web shells and conduct system and network reconnaissance before downloading additional payloads. They have used legitimate cloud storage services to deliver malicious files and abused DLL sideloading to execute malicious code in memory.

Warlock has also used the BYOVD (Bring Your Own Vulnerable Driver) technique by deploying the vulnerable K7RKScan.sys driver (CVE-2025-1055) to disable security software. Legitimate tools and built-in features, including Microsoft Visual Studio Code tunnels, have been abused for remote access and command execution.

In one incident, the attackers distributed a security-disabling tool to at least 40 hosts before staging the Warlock ransomware through the domain’s SYSVOL share, allowing it to spread across multiple systems. The activity ultimately involved network discovery, payload deployment, security tool termination, lateral movement, and ransomware execution.

Recommendation

Ensure all on-premises Microsoft SharePoint Server systems are fully patched against known and actively exploited vulnerabilities, including ToolShell-related flaws. Monitor SharePoint servers for unusual web shells, ASP.NET machine-key access, suspicious PowerShell or command execution, VS Code tunnels, and unauthorized changes to SYSVOL.

Organizations should also monitor for vulnerable drivers such as K7RKScan.sys, restrict unnecessary cloud file-sharing services, maintain updated endpoint protection, and review privileged accounts and network activity for signs of lateral movement.

Source

https://thehackernews.com/2026/10/warlock-exploits-sharepoint-flaws-to.html