مركز جمع المعلومات

معلومات التهديدات

Warlock ransomware is still walking in through SharePoint.

Symantec reports Warlock (Storm-2603) hit at least four organizations in two months, including a water utility and a telecom provider. One intrusion disabled security tools on 40+ hosts in about two hours and deployed ransomware via SYSVOL.

هذا التقرير متاح بالإنجليزية فقط.

Symantec reports that the Warlock ransomware group is still getting in through SharePoint. In the past two months it has compromised at least four organizations: a water utility, a telecommunications provider, a regional government body and a university. Targets sit in Portuguese- and Spanish-speaking countries across Europe, Africa and Latin America. SecurityWeek and The Hacker News carried the findings.


Warlock is tracked by Symantec as Longlegs and by Microsoft as Storm-2603. It first drew attention in mid-2025 with the ToolShell SharePoint zero-days. The latest intrusions show the same entry point still works against unpatched servers. Symantec says exploitation of ToolShell and related SharePoint flaws "remains a viable initial access route."


Two of the victims run critical infrastructure. A one-year-old patch gap on an internet-facing SharePoint server is enough to put a water or telecom operator in the ransomware queue.


Technical detail. Reported tradecraft covers the full chain:


Initial access: exploitation of SharePoint vulnerabilities to drop a web shell and run code inside the SharePoint application pool. Reporting also ties the activity to ASP.NET machine key theft.


Persistence and tooling: DLL sideloading for in-memory execution, and Visual Studio Code tunnels, with code-insiders.exe installed as a service.


Defense evasion: a vulnerable signed driver abused to terminate security software before encryption.


Deployment: in one intrusion against a critical infrastructure operator, the tool that disables security software was pushed to at least 40 hosts in about two hours. Warlock was then staged in the domain SYSVOL share, so normal domain replication delivered it. It ran on at least 33 hosts.


Why it matters. The SYSVOL staging step means the payload rides legitimate replication. Once an attacker holds domain-level write access, the blast radius is the whole domain within hours.


Recommended mitigation:


Patch all on-premises SharePoint servers to current builds, and rotate ASP.NET machine keys after any suspected compromise.


Take unpatched SharePoint servers off the internet until they are fixed.


Alert on new or modified files in SYSVOL, especially executables and scripts.


Alert on code-insiders.exe or other VS Code tunnel binaries running as a service on servers.


Enable vulnerable driver blocklisting and tamper protection on endpoint security tooling.


Hunt for web shells in SharePoint layouts directories and for unusual child processes of the SharePoint worker process (w3wp.exe).

يتطلب صلاحية دخول.

سجل الأحداث المشفّر الكامل وإجراءات المعالجة متاحة بعد تسجيل الدخول.