The Warlock ransomware group has continued to exploit vulnerabilities in Microsoft’s SharePoint platform, targeting critical infrastructure, government, and education entities worldwide. This latest development is a worrying trend for organizations that have not yet patched or mitigated the known flaws.
According to Symantec researchers, the China-based hacking group Longlegs, also tracked as Storm-2603, has been linked to several malicious operations in the past year. Last October, the same group was seen exploiting SharePoint vulnerabilities, including ToolShell, just two weeks before public disclosure. This initial attack compromised over 400 servers and marked a significant escalation of the threat landscape.
Fast forward to this year, and it appears that Storm-2603 has continued to favor the exploitation of SharePoint bugs in its attacks. In addition to ToolShell, the group’s arsenal may include recent flaws such as CVE-2026-32201, CVE-2026-45659, and others. These vulnerabilities have been actively exploited by the group over the past two months, with at least four victim organizations affected in Portuguese- and Spanish-speaking countries.
The attacks typically follow a predictable pattern: after exploiting the SharePoint flaw, the hacking group deploys a webshell to gain remote access, exfiltrates sensitive data, and executes Warlock ransomware on compromised systems. In some cases, the group has also been observed using Visual Studio Code’s built-in tunnel feature to establish covert network access.
The use of DLL sideloading for in-memory code execution and living-off-the-land tools for reconnaissance and command execution are also part of Storm-2603’s arsenal. Furthermore, the threat actor stages the Warlock payload inside the domain’s SYSVOL share, which is automatically replicated across all domain controllers, making it easier to execute the file-encrypting ransomware at scale.
The continued activity of Longlegs and its exploitation of ToolShell and other related SharePoint vulnerabilities highlights the importance of patching and mitigating these known flaws. As Symantec notes, “exploitation of ToolShell and other related SharePoint vulnerabilities remains a viable initial access route for attackers on SharePoint deployments that have not been patched or otherwise mitigated.”
For organizations using SharePoint, it is essential to take immediate action by applying available patches and hardening their configurations against potential attacks. This includes implementing robust authentication mechanisms, limiting network access to only necessary services, and conducting regular security audits to identify potential vulnerabilities. By taking these precautions, organizations can significantly reduce the risk of falling victim to Warlock ransomware and other similar threats.
Source: SecurityWeek — 2026-10-02