Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware
Warlock ransomware attackers exploit Microsoft SharePoint vulnerabilities to gain initial access, disable security tools and distribute ransomware across critical infrastructure networks.

The threat actor behind Warlock ransomware is continuing to exploit vulnerabilities in internet-facing Microsoft SharePoint servers, targeting critical infrastructure, government and education organizations.
According to Symantec and Carbon Black researchers, the group—tracked as Longlegs, and also associated with names including Storm-2603 and Gold Salem—attacked at least four organizations during the past two months. Victims included a water utility, telecommunications provider, regional government body and university across Portuguese- and Spanish-speaking countries in Europe, Africa and Latin America.
SharePoint Remains the Initial Access Point
Warlock gained prominence in 2025 after exploiting the Microsoft SharePoint vulnerabilities collectively known as ToolShell.
The original chain involved vulnerabilities including:
| CVE | Role |
|---|---|
| CVE-2025-49704 | Remote Code Execution |
| CVE-2025-49706 | Authentication/Spoofing weakness |
| CVE-2025-53770 | Related SharePoint RCE |
| CVE-2025-53771 | Related SharePoint vulnerability |
These vulnerabilities affect on-premises SharePoint Server, not SharePoint Online in Microsoft 365. Microsoft previously warned that unpatched internet-facing SharePoint servers would continue to attract exploitation.
Symantec says Warlock's more recent intrusions appear to involve exploitation of multiple SharePoint vulnerabilities, potentially including both older and newer flaws.
From SharePoint to Ransomware
After gaining access, the attackers deploy web shells and attempt to obtain the SharePoint farm's ASP.NET machine keys. Those keys can then be abused to create validly signed payloads and execute code inside the SharePoint application pool.
The broader attack sequence looks like:
Vulnerable SharePoint → Web Shell → Machine Key Theft → Code Execution → Network Discovery → Security Tool Disablement → Lateral Movement → Warlock Ransomware
Attackers have also used legitimate services and living-off-the-land techniques to reduce their visibility.
Security Tools Disabled on 40 Hosts
In one attack against a critical infrastructure operator, the attackers distributed a tool designed to disable security software to at least 40 systems in roughly two hours.
Warlock ransomware was subsequently deployed to at least 33 hosts. The attackers placed the ransomware inside the organization's SYSVOL share, allowing normal Active Directory domain replication to help distribute the payload across systems.
The group has also used the Bring Your Own Vulnerable Driver (BYOVD) technique.
Researchers observed exploitation of the legitimate but vulnerable K7RKScan.sys driver, associated with CVE-2025-1055, to terminate security products.
Legitimate Tools Help Attackers Stay Hidden
Warlock operators have incorporated several legitimate tools and services into their attacks, including:
- Visual Studio Code tunnels for remote access
- Velociraptor for command-and-control activity
- Cloud storage and file-sharing services for payload delivery
- DLL sideloading for malicious code execution
- Windows command-line and other living-off-the-land utilities
- SYSVOL and domain replication for ransomware distribution
Microsoft previously observed Storm-2603 using Mimikatz against LSASS, PsExec, WMI and Group Policy Objects during SharePoint-based ransomware intrusions.
What Organizations Should Do
Organizations operating on-premises SharePoint should prioritize:
- Applying all current Microsoft SharePoint security updates.
- Removing unnecessary internet exposure.
- Hunting for suspicious
.aspxweb shells. - Reviewing SharePoint and IIS logs for exploitation attempts.
- Monitoring for unexpected ASP.NET machine-key access.
- Detecting suspicious VS Code tunnel activity.
- Blocking known vulnerable drivers.
- Monitoring attempts to disable EDR or antivirus products.
- Reviewing SYSVOL and Group Policy for unauthorized modifications.
- Isolating systems immediately if ransomware preparation activity is detected.
Because attackers may establish persistence after initial exploitation, simply patching SharePoint may not be sufficient if the server was already compromised. Microsoft has previously documented scheduled tasks, IIS manipulation and additional persistence mechanisms following SharePoint exploitation.
Security Takeaway
The latest Warlock activity demonstrates that unpatched on-premises SharePoint servers remain a valuable entry point for ransomware operators, even more than a year after the original ToolShell exploitation wave.
The most concerning progression is:
SharePoint Exploit → Security Tools Disabled → Domain-Wide Distribution → Warlock Ransomware
Organizations should therefore treat exposed SharePoint vulnerabilities as potential entry points to a broader Active Directory compromise rather than simply as isolated web-server issues.
Related reporting
Apple CoreGraphics Zero-Day PoC Emerges as WhatsApp PDF Checks Raise Delivery Questions
A public PoC for Apple CoreGraphics CVE-2026-86950 demonstrates memory corruption through a malicious PDF, while new WhatsApp PDF protections raise questions about a possible delivery path.
Kiteworks Fixes Critical Vulnerability Discovered During Emergency Shutdown
Kiteworks patched a previously unknown critical vulnerability discovered during a nine-hour precautionary shutdown prompted by intelligence about a potential cyberattack, with no evidence of exploitation.
TeamFiltration Campaign Compromises Microsoft 365 Service Accounts Using Default Passwords
TeamFiltration attackers targeted over 5,700 Microsoft 365 accounts across 28 tenants, compromising seven unmanaged service accounts using default or unrotated passwords without MFA.


