Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Satellite data reveal massive scale of routine oil pollution in oceans. See the map

    October 3, 2026

    Utilities are public services – and should not be run as businesses | Utilities

    October 3, 2026

    Was Christa Pike’s execution team all women? We investigated

    October 3, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Satellite data reveal massive scale of routine oil pollution in oceans. See the map
    • Utilities are public services – and should not be run as businesses | Utilities
    • Was Christa Pike’s execution team all women? We investigated
    • French Unrest: Are we witnessing a new ‘Yellow Vests’ movement? – Spotlight
    • ICE Has Been Dumping Protester Photos Into a Palantir Database
    • Warlock Expands SharePoint Exploitation in Critical Infrastructure Attacks
    • Absa Becomes First African Bank To Custody Bitcoin
    • Long-Awaited Senate Deal to Speed Permitting Faces Familiar Hurdles
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Saturday, October 3
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Warlock Expands SharePoint Exploitation in Critical Infrastructure Attacks

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKOctober 3, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    The Warlock ransomware group continues to target SharePoint servers in attacks against critical infrastructure, government, and education entities, Symantec reports.

    Warlock is believed to be operated by a China-based hacking group tracked as Longlegs and Storm-2603, which has been linked to malicious operations such as CL-CRI-1040, CamoFei, and ChamelGang.

    Last year, the Chinese state-sponsored groups Linen Typhoon and Violet Typhoon were seen exploiting two SharePoint vulnerabilities dubbed ToolShell as zero-days at least two weeks before public disclosure.

    Within weeks, more than 400 SharePoint servers were compromised, and Storm-2603’s exploitation of ToolShell stood out amid heavy APT activity.

    By October 2025, researchers uncovered numerous Warlock ransomware attacks that exploited ToolShell. Some of the group’s victims included a Middle East telecom firm, African and South American government entities, and a US university.

    According to a fresh Symantec report, Storm-2603 continues to favor the exploitation of SharePoint bugs in attacks. In addition to ToolShell, its arsenal may also include recent flaws such as CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, CVE-2026-58644, CVE-2026-50522, and CVE-2026-55040.

    Advertisement. Scroll to continue reading.

    Over the past two months, the Warlock operator has hit at least four victim organizations in Portuguese- and Spanish-speaking countries.

    “The victims included two critical infrastructure operators, a water utility and a telecommunications provider, along with a regional government body and a university,” Symantec reports.

    As part of one intrusion, the hacking group deployed a tool to disable the security software on at least 40 systems and then executed Warlock on at least 33 of them.

    The group’s exploitation of SharePoint flaws is typically followed by webshell deployment, ASP.NET machine key exfiltration, and the deployment of a forced signed payload for remote code execution (RCE).

    Storm-2603 relies on DLL sideloading for in-memory code execution, drops additional payloads from legitimate file-sharing and storage services and a vulnerable driver to disable security tools, and relies on living-off-the-land tools for reconnaissance and command execution.

    “The group has also been observed abusing Visual Studio Code’s built-in tunnel feature, installing the code-insiders.exe binary as a service to establish covert remote network access that blends into traffic that typically originates from developer or administrator workstations,” Symantec notes.

    Additionally, the threat actor stages the Warlock payload inside the domain’s SYSVOL share, which is automatically replicated to every domain controller and is readable domain-wide, to execute the file-encrypting ransomware at scale.

    “Longlegs’ continued activity, more than a year after Warlock ransomware first came to prominence, shows that exploitation of ToolShell and other related SharePoint vulnerabilities remains a viable initial access route for attackers on SharePoint deployments that have not been patched or otherwise mitigated,” Symantec notes.

    Related: Russian APT Star Blizzard Uses ‘RedFlick’ Infection Chain in Recent Attacks

    Related: Hackers Use ChatGPT Custom GPTs in ClickFix Attacks

    Related: Daemon Tools Hackers’ NeedyMantis Malware Dissected by Microsoft

    Related: SmarterTools Hit by Ransomware via Vulnerability in Its Own Product

    attacks critical expands exploitation infrastructure SharePoint Warlock
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    In Rare Move, Alleged Iranian State Hacker Extradited to US

    Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes

    Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign

    Wall Street giant BNY discusses infrastructure tie-up with Kraken parent Payward

    Crypto Scammers Hijack Microsoft’s Official X Account

    Is It Fair to Blame ‘Rogue’ AI for Security Failures?

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Satellite data reveal massive scale of routine oil pollution in oceans. See the map

    October 3, 2026

    Utilities are public services – and should not be run as businesses | Utilities

    October 3, 2026

    Was Christa Pike’s execution team all women? We investigated

    October 3, 2026

    French Unrest: Are we witnessing a new ‘Yellow Vests’ movement? – Spotlight

    October 3, 2026
    Latest Posts

    Lime bikes hurtling around the city: is this the revenge of a priced-out generation? | Andy Beckett

    August 8, 2026

    Clarity Act Delayed Until September, Trump Praises Bitcoin

    August 8, 2026

    North Carolina Ports confirms cyberattack disrupting operations

    August 8, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Satellite data reveal massive scale of routine oil pollution in oceans. See the map

    October 3, 2026

    Utilities are public services – and should not be run as businesses | Utilities

    October 3, 2026

    Was Christa Pike’s execution team all women? We investigated

    October 3, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.