Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Conservatives pledge to scrap £100,000 childcare ‘cliff edge’

    October 3, 2026

    Tories plan to expand free childcare to high earners to end ‘cliff edge’ | Conservatives

    October 3, 2026

    Google Wallet not working on your Pixel? 4 ways to fix tap-to-pay

    October 3, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Conservatives pledge to scrap £100,000 childcare ‘cliff edge’
    • Tories plan to expand free childcare to high earners to end ‘cliff edge’ | Conservatives
    • Google Wallet not working on your Pixel? 4 ways to fix tap-to-pay
    • The State of Cybersecurity in 2026: Key Segments, Insights, and Innovations
    • OpenPayd eyes more acquisitions as it targets year-end Nasdaq listing and U.S. launch
    • Scientists just made a superconductor stronger using “empty space”
    • UK-Iranian dual national arrested over RAF Fairford investigation bailed
    • 20% Off Brooks Promo Code | October 2026
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Saturday, October 3
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKOctober 3, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananOct 03, 2026Vulnerability / Critical Infrastructure

    The suspected China-linked threat actor known as Warlock is still continuing to weaponize Microsoft SharePoint vulnerabilities, likely both old and new, in attacks targeting organizations in Portuguese- and Spanish-speaking countries.

    The activity, observed by the Symantec and Carbon Black Threat Hunter Team, has hit critical infrastructure, government, and education organizations.

    “In the past two months, Longlegs has attacked at least four organizations, including two critical infrastructure operators (a water utility and a telecommunications provider), a regional government body, and a university,” the Broadcom-owned cybersecurity unit said. “Victims were in Portuguese- and Spanish-speaking countries, spanning Europe, Africa, and Latin America.”

    Warlock, also tracked as Gold Salem, Longlegs, and Storm-2603, gained prominence in mid-2025 in connection with the zero-day exploitation of the “ToolShell” SharePoint flaws to deploy ransomware on targeted systems.

    Cybersecurity

    Earlier this year, the group was linked to the compromise of SmarterTools by exploiting an unpatched SmarterMail instance. It has also relied on legitimate tools like Velociraptor for command-and-control (C2) and the bring your own vulnerable driver (BYOVD) technique to disarm security software running on a compromised host.

    According to Symantec, Warlock shares overlaps with older activity clusters known as CL-CRI-1040, CamoFei, and ChamelGang.

    “In one intrusion against a critical infrastructure operator, the attackers pushed a tool designed to disable security software to at least 40 hosts within about two hours, then deployed Warlock on at least 33 hosts by staging it in the domain’s SYSVOL share, where ordinary domain replication delivered it to machines,” the researchers said.

    Attacks mounted by Warlock have leveraged multiple vulnerabilities in on-premises Microsoft SharePoint Server deployments. Upon successfully finding a way in, the threat actors have been found to drop web shells that can target multiple versions of SharePoint.

    The end goal of the web shell is to collect the SharePoint farm’s ASP.NET machine keys, which are then abused to forge a validly signed payload and achieve remote code execution inside the SharePoint application pool.

    Some of the other observed tactics are listed below –

    • Using DLL sideloading to load malicious code into memory.
    • Downloading follow-on payloads from legitimate cloud file-sharing and storage services such as catbox[.]moe and wasabisys[.]com to fly under the radar.
    • Abusing a legitimate-but-vulnerable driver K7RKScan.sys (CVE-2025-1055) as part of a BYOVD attack to disable security software. The same driver was previously exploited by DragonForce ransomware actors.
    • Using living-off-the-land (LotL) tooling to perform reconnaissance and run commands on the compromised hosts. This includes the abuse of Microsoft Visual Studio Code’s built-in tunnel feature to facilitate remote connections to infected systems.
    • Staging payloads inside the compromised domain’s SYSVOL share to deploy ransomware at scale.
    Cybersecurity

    As recently as July 22, 2026, the threat actors are said to have exploited SharePoint Server flaws to drop a web shell, conduct discovery, obtain arbitrary code execution inside the SharePoint application pool, deploy additional payloads, burrow deeper into the network, establish VS Code tunnels, terminate security software, and ultimately deploy the ransomware binary.

    “Longlegs’ continued activity, more than a year after Warlock ransomware first came to prominence, shows that exploitation of ToolShell and other related-SharePoint vulnerabilities remains a viable initial access route for attackers SharePoint deployments that have not been patched or otherwise mitigated,” Symantec and Carbon Black said.

    “The apparent recent focus on Portuguese- and Spanish-speaking countries suggests either an opportunistic targeting pattern driven by exposed, vulnerable SharePoint servers, or a more deliberate tasking.”

    Deploy disable exploits flaws ransomware Security SharePoint Tools Warlock
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    The State of Cybersecurity in 2026: Key Segments, Insights, and Innovations

    MI5 Says China’s MSS Funded Research Involving 100+ U.K.-Linked Academics

    Fortra Patches Critical Vulnerabilities in BoKS

    Danish university DTU breach exposes data of up to 200,000 people

    doxx.net Raises $38 Million to Prevent AI Agent-on-the-Internet Misadventures

    Kiteworks patches max severity code injection vulnerability

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Conservatives pledge to scrap £100,000 childcare ‘cliff edge’

    October 3, 2026

    Tories plan to expand free childcare to high earners to end ‘cliff edge’ | Conservatives

    October 3, 2026

    Google Wallet not working on your Pixel? 4 ways to fix tap-to-pay

    October 3, 2026

    The State of Cybersecurity in 2026: Key Segments, Insights, and Innovations

    October 3, 2026
    Latest Posts

    Google’s top hacker hunter explains why hacking groups get codenames

    August 8, 2026

    Nicola Sturgeon ‘has not spoken to’ estranged husband, Peter Murrell, since he was jailed | Nicola Sturgeon

    August 8, 2026

    Amid Abuse Claims Against Max Miller, This Democrat Thinks He Can Win His Seat

    August 8, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Conservatives pledge to scrap £100,000 childcare ‘cliff edge’

    October 3, 2026

    Tories plan to expand free childcare to high earners to end ‘cliff edge’ | Conservatives

    October 3, 2026

    Google Wallet not working on your Pixel? 4 ways to fix tap-to-pay

    October 3, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.