Warlock Expands SharePoint Exploitation in Critical Infrastructure Attacks

https://www.securityweek.com/wp-content/uploads/2023/06/SharePoint-Ransomware-attack.jpg

The Warlock ransomware group continues to target SharePoint servers in attacks against critical infrastructure, government, and education entities, Symantec reports.

Warlock is believed to be operated by a China-based hacking group tracked as Longlegs and Storm-2603, which has been linked to malicious operations such as CL-CRI-1040, CamoFei, and ChamelGang.

Last year, the Chinese state-sponsored groups Linen Typhoon and Violet Typhoon were seen exploiting two SharePoint vulnerabilities dubbed ToolShell as zero-days at least two weeks before public disclosure.

Within weeks, more than 400 SharePoint servers were compromised, and Storm-2603’s exploitation of ToolShell stood out amid heavy APT activity.

By October 2025, researchers uncovered numerous Warlock ransomware attacks that exploited ToolShell. Some of the group’s victims included a Middle East telecom firm, African and South American government entities, and a US university.

According to a fresh Symantec report, Storm-2603 continues to favor the exploitation of SharePoint bugs in attacks. In...

Copyright of this story solely belongs to www.securityweek.com. To see the full text click HERE

Read more