Direct answer: A suspected China-linked ransomware group known as Warlock (also tracked as Longlegs, Gold Salem, and Storm-2603) is actively exploiting both old and new Microsoft SharePoint vulnerabilities to break into critical infrastructure organizations. According to research from Symantec’s Threat Hunter Team published on October 1, 2026, the group hit at least four organizations in the past two months, a water utility, a telecom provider, a regional government body, and a university. In one intrusion, attackers disabled security software on 40 hosts in about two hours, then encrypted 33 machines, a chain that ran nine days from first webshell to full network takeover.
If you run SharePoint Server on premises and have not applied the latest updates, this one deserves your attention today.
Who Is Warlock (Storm-2603)?
Warlock is not a new name on the threat landscape. The group gained prominence in mid-2025 when it exploited the “ToolShell” SharePoint zero-day flaws to deploy ransomware at scale. Security researchers at Symantec and Carbon Black track the same actor under several aliases: Longlegs, Gold Salem, and Microsoft’s designation Storm-2603.
What makes the current wave notable is persistence. More than a year after ToolShell, the group is still finding internet-facing SharePoint servers that were never properly patched and is combining those with newer vulnerabilities disclosed in 2026.
The researchers assess the actor as China-nexus, though no government has publicly attributed these specific attacks to a state sponsor. Warlock shares operational overlaps with older clusters known as CL-CRI-1040, CamoFei, and ChamelGang.
What Happened: The October 2026 Campaign
Symantec’s Threat Hunter Team observed at least four confirmed intrusions over the past two months:
- A water utility (critical infrastructure)
- A telecommunications provider (critical infrastructure)
- A regional government body
- A university
Victims were located in Portuguese- and Spanish-speaking countries across Europe, Africa, and Latin America. Symantec notes the geographic clustering may simply reflect where vulnerable servers were exposed to the internet rather than a deliberate targeting choice.
CVE-2026-45659 has since been added to CISA’s Known Exploited Vulnerabilities catalog. CISA has separately flagged active exploitation of three on-premises SharePoint flaws: CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164.
How the Attack Chain Works, Step by Step
This is what distinguishes Warlock’s operations from opportunistic ransomware: a patient, multi-stage intrusion that uses legitimate tools at every step, making detection harder.
1. Initial access through a vulnerable SharePoint Server
The group exploits internet-facing on-premises SharePoint deployments, using both the year-old ToolShell vulnerabilities and newer 2026 flaws. Patch level is what matters here, not the specific CVE: unpatched servers are the common denominator.
2. A webshell that steals the server’s signing keys
Once inside, Warlock drops a webshell into SharePoint’s LAYOUTS directory, targeting multiple SharePoint versions at once so it works regardless of which version is installed. The webshell’s real job is to harvest the SharePoint farm’s ASP.NET machine keys. With those keys, attackers forge a validly signed payload, which they then execute as code inside the SharePoint application pool. Your own server’s signing infrastructure becomes their remote code execution primitive.
3. Quiet lateral movement with legitimate tools
From there the group moves like an administrator: DLL sideloading for additional payloads (staged on ordinary file hosts such as catbox.moe and wasabisys.com so traffic blends in), Visual Studio Code tunnels installed as a service for remote access that looks like developer activity, and NetExec for Active Directory mapping and remote command execution.
4. Killing your security software before you notice
This is the signature move. Warlock uses a signed but vulnerable driver, K7RKScan, in a “bring your own vulnerable driver” (BYOVD) attack to terminate security processes at the kernel level. In one intrusion against a critical infrastructure operator, the attackers pushed their disabling tool to at least 40 hosts within about two hours, before deploying any ransomware at all. With endpoint defenses dead, encryption becomes a formality.
5. Encrypting via the domain’s own file replication
The ransomware payloads were staged in the domain’s SYSVOL share, which domain controllers synchronize automatically. Ordinary domain replication then delivered the malware to machines across the network. At least 33 hosts were encrypted in the documented intrusion. From the first webshell on July 22, 2026 to full encryption, the entire chain ran about nine days.
Why SharePoint Server Remains Such a Target
The pattern is familiar from other enterprise-software campaigns. On-premises SharePoint Server is internet-facing at many organizations, patching lags, and the software runs with enough privilege to make a webshell devastating. Earlier this year, the same group compromised the IT vendor SmarterTools by exploiting an unpatched SmarterMail instance, showing the group actively hunts neglected enterprise software.
The lesson from Symantec’s report is that attackers now assume organizations rely on endpoint detection. Warlock’s entire playbook is built around neutralizing EDR first: the BYOVD driver, legitimate admin tools, and tunnels that mimic developer workflows. If your defense strategy starts and ends with “our EDR will catch it,” this campaign is a counterexample.
What to Do Right Now
If you administer on-premises SharePoint Server, take these steps immediately:
- Apply Microsoft’s latest SharePoint security updates to every server in the farm, and verify the patches actually applied. CISA’s advisory specifically covers CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164.
- Enable AMSI integration for each SharePoint application and turn on full request body scanning where possible. This helps catch malicious payloads the application processes.
- Reduce internet exposure. Limit direct exposure of SharePoint servers to the internet and block external access to Central Administration. No reason for the admin interface to face the public web.
- Hunt for webshells. Check the LAYOUTS directories for unexpected files, review for unknown Visual Studio Code tunnel services, and look for the K7RKScan driver or other unfamiliar signed drivers loading on endpoints.
- Rotate ASP.NET machine keys if you suspect compromise. Since Warlock’s chain depends on stolen machine keys to forge signed payloads, a key rotation after patching cuts that avenue off.
- Test your backups against the SYSVOL vector. Because the payload spread through domain replication, restoring individual machines is not enough; verify that clean backups exist outside the compromised domain structure.
- Assume the group is opportunistic. You do not need to be in the targeted regions. Any internet-exposed, unpatched SharePoint Server is in scope.
This story fits a pattern we have covered repeatedly in 2026: enterprise infrastructure software with a known flaw, a long patch lag, and attackers willing to be patient. The Cisco SD-WAN and F5 BIG-IP zero-days earlier this year followed the same arc, internet-facing admin software, delayed patching, real-world exploitation. SharePoint Server now joins that list, alongside other recently patched critical flaws like the GitLab AI Gateway vulnerability and the FortiMail zero-day.
FAQ
What is the Warlock ransomware group?
Warlock is a suspected China-linked ransomware operation also tracked as Longlegs, Gold Salem, and Storm-2603. It gained prominence in mid-2025 exploiting the ToolShell SharePoint zero-days and continues to target critical infrastructure through SharePoint vulnerabilities as of October 2026.
Which SharePoint vulnerabilities is Warlock exploiting?
According to Symantec research published in October 2026, the group exploits both the older ToolShell SharePoint flaws and newer 2026 vulnerabilities. CISA has flagged active exploitation of CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164 in on-premises SharePoint Server, and added CVE-2026-45659 to its Known Exploited Vulnerabilities catalog.
How does Warlock disable security software?
The group uses a “bring your own vulnerable driver” (BYOVD) technique with a signed but vulnerable driver called K7RKScan to terminate endpoint security processes at the kernel level. In one documented intrusion, the disabling tool reached at least 40 hosts within about two hours before ransomware was deployed.
Is Microsoft 365 or SharePoint Online affected?
No. The reported attacks target on-premises Microsoft SharePoint Server deployments, typically those exposed to the internet and missing patches. SharePoint Online in Microsoft 365 is patched and managed by Microsoft and is not affected by these specific flaws.
What should SharePoint Server administrators do today?
Install the latest Microsoft SharePoint security updates on all servers and verify they applied, enable AMSI and full request body scanning, restrict internet exposure (especially Central Administration), hunt for webshells and rogue VS Code tunnel services, and rotate ASP.NET machine keys if compromise is suspected.
