Warlock exploits SharePoint vulnerabilities to disable security tools
A threat actor tracked as Warlock is using SharePoint vulnerabilities to drop web shells, disable endpoint defenses, and stage ransomware across networks, according to The Hacker News and Symantec and Carbon Black.
The Hacker News reports that the threat actor known as Warlock is continuing to exploit on-premises Microsoft SharePoint servers to drop web shells, obtain code execution in the SharePoint application pool, and eventually deploy ransomware. According to Symantec and Carbon Black Threat Hunter Team, recent intrusions targeted critical infrastructure, government, and education organizations in Portuguese- and Spanish-speaking countries.
What the reporters observed
Researchers said Warlock, also tracked as Gold Salem, Longlegs, and Storm-2603, has been weaponizing both ToolShell and other SharePoint-related flaws. The intrusions include dropping web shells that are used to collect ASP.NET machine keys from the SharePoint farm, then forging signed payloads to run code inside the SharePoint application pool, according to Symantec and Carbon Black.
The group has hit multiple sectors: Symantec and Carbon Black reported attacks against a water utility, a telecommunications provider, a regional government body, and a university. In one incident, the attackers pushed a tool that disabled security software to at least 40 hosts within about two hours, then staged the ransomware in the domain's SYSVOL share, where normal domain replication caused it to reach dozens of machines.
Warlock's activity also includes a range of techniques that make detection harder: DLL sideloading to run code in memory, downloading follow-on payloads from public cloud file-sharing services, and using living-off-the-land tooling for discovery and control. The researchers noted the group has abused Microsoft Visual Studio Code's built-in tunnel feature to maintain remote connections to infected systems.
How the attacks work, in practical terms
According to the reporting, the chain typically starts with a SharePoint server vulnerability that lets the attackers drop a web shell. That web shell is then used to gather machine keys, forge a signed payload, and gain arbitrary code execution in the SharePoint application pool. From there, the attackers move laterally and escalate their reach inside the network.
Observed follow-on techniques include:
- Staging ransomware in SYSVOL so domain replication spreads the payload.
- Using a vulnerable driver, K7RKScan.sys (noted as CVE-2025-1055 in the report), for a bring-your-own vulnerable driver attack that helps disable security software.
- Pulling additional malware from public cloud file-sharing and storage services to blend with legitimate traffic.
- Setting up VS Code tunnels and other remote-access channels for persistent control.
These tactics enabled the actors to disable defenses quickly and deploy ransomware broadly in some cases, according to Symantec and Carbon Black.
Why SharePoint vulnerabilities matter for small and public organizations
If you run on-premises SharePoint, the attack pattern here matters because the entry point is often an exposed, unpatched server. The Hacker News coverage and the Symantec and Carbon Black analysis show that once attackers can run web shells in a SharePoint environment, they have a path to forge payloads, bypass some application-level controls, and stage tools for broad distribution across a domain.
Organizations that use on-premises Microsoft infrastructure should treat exposed SharePoint instances as high-risk assets, especially where domain-level shares like SYSVOL can be used to reach many endpoints.
What you should do now
Follow these practical, general steps based on the techniques Symantec and Carbon Black described:
- Inventory and patch or mitigate on-premises SharePoint servers, prioritizing any internet-exposed instances.
- Scan SYSVOL and other domain shares for unexpected files, scripts, or newly added binaries and remove anything you did not place there.
- Hunt for signs of web shells and checks for unexpected access to ASP.NET machine keys or other SharePoint configuration artifacts.
- Look for signs of BYOVD use, including presence of the K7RKScan.sys driver, and remove or block vulnerable drivers; restrict driver installation to trusted admins.
- Monitor for unusual use of legitimate tools like Visual Studio Code tunnels and Velociraptor, and treat unexpected remote tunnels as an incident indicator.
- Review backup integrity and incident response plans so you can restore systems without paying ransom if needed.
- Limit who can write to SYSVOL and other replication paths, and reduce the number of accounts with broad domain privileges.
If you want a quick external check of how exposed your site is, start with a free external scan on our security page: /security.html.
Detection and longer term hardening
Because Warlock used public cloud file-sharing services to fetch follow-on payloads, network and proxy logs are useful for spotting anomalous downloads from places you do not normally use. Checking endpoint telemetry for DLL sideloading attempts and for unexpected termination of security agents can help detect activity early.
Symantec and Carbon Black highlighted that the actors reused some older techniques alongside newer ones. That means regular patching, reducing attack surface (for example, removing unnecessary internet-facing SharePoint instances), and hardening replication shares are practical steps that reduce risk over time.
Where this leaves you
The report from The Hacker News, based on Symantec and Carbon Black analysis, shows that SharePoint vulnerabilities remain a viable initial access route when servers are unpatched or exposed. The combination of web shells, SYSVOL staging, and methods to disable security software creates conditions where ransomware can spread quickly. Treat internet-facing and on-premises SharePoint instances as high-priority for patching and monitoring, and follow the detection and hardening steps above to reduce your risk.
For the original technical writeup, see The Hacker News report: https://thehackernews.com/2026/10/warlock-exploits-sharepoint-flaws-to.html
Sources
This post was drafted with AI from the reporting linked above and published by Jones Web Designs. For full details, read the original sources.