Executive Summary
The China-linked threat actor Warlock (also known as Gold Salem, Longlegs, and Storm-2603) continues to exploit Microsoft SharePoint vulnerabilities to deploy ransomware against critical infrastructure organizations in Portuguese and Spanish-speaking countries. In recent attacks observed through October 2026, Warlock targeted water utilities, telecommunications providers, government bodies, and universities across Europe, Africa, and Latin America. The group leverages web shells to extract SharePoint farm ASP.NET machine keys, uses legitimate tools like Velociraptor for command-and-control, and employs bring-your-own-vulnerable-driver techniques to disable security software before deploying ransomware at scale through domain SYSVOL shares.
This incident highlights the persistent threat of unpatched SharePoint deployments and the evolving sophistication of state-sponsored ransomware operations targeting critical infrastructure sectors globally.
Why This Matters Now
Warlock's continued exploitation of SharePoint vulnerabilities over 15 months demonstrates that critical infrastructure organizations remain vulnerable to sophisticated nation-state ransomware attacks, with recent targeting of water utilities and telecommunications providers showing escalating risks to essential services.
Attack Path Analysis
Warlock exploited unpatched SharePoint Server vulnerabilities to deploy web shells and collect ASP.NET machine keys for code execution. The attackers escalated privileges through the SharePoint application pool, moved laterally using SYSVOL shares and domain replication, established command and control via Visual Studio Code tunnels and legitimate cloud services, exfiltrated data through covert channels, and deployed ransomware at scale while disabling security software using BYOVD techniques.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Threat actors exploited multiple vulnerabilities in on-premises Microsoft SharePoint Server deployments to gain initial access and deploy web shells targeting multiple SharePoint versions
Related CVEs
CVE-2025-1055
CVSS 5.6A privilege escalation vulnerability in K7RKScan.sys driver allows attackers to disable security software using bring-your-own-vulnerable-driver (BYOVD) technique.
Affected Products:
K7 Computing K7RKScan.sys Driver – < patched version
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Web Shell
DLL Side-Loading
Disable or Modify Tools
Ingress Tool Transfer
Remote Desktop Protocol
Data Encrypted for Impact
File and Directory Discovery
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Software security patches and updates
Control ID: 6.2.4
NYDFS 23 NYCRR 500 – Penetration Testing and Vulnerability Assessments
Control ID: 500.15
DORA – ICT risk management framework
Control ID: Article 11
CISA ZTMM 2.0 – Network/Environment
Control ID: Pillar 3
NIS2 Directive – Cybersecurity measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Utilities
Critical infrastructure water utilities face ransomware targeting SharePoint vulnerabilities, with attackers disabling security tools across 40+ hosts within hours.
Telecommunications
Telecom providers experience targeted ransomware attacks exploiting SharePoint flaws, leveraging SYSVOL domain replication for rapid deployment across network infrastructure.
Government Administration
Regional government bodies suffer SharePoint zero-day exploitation enabling web shell deployment, security software termination, and ransomware distribution via domain controllers.
Higher Education/Acadamia
Universities face Warlock ransomware campaigns targeting SharePoint servers, using legitimate cloud services and vulnerable drivers to bypass security controls.
Sources
- Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomwarehttps://thehackernews.com/2026/10/warlock-exploits-sharepoint-flaws-to.htmlVerified
- Symantec Threat Intelligence Report on Warlock Ransomwarehttps://www.security.com/threat-intelligence/warlock-ransomware-critical-infrastructureVerified
- CISA Known Exploited Vulnerabilities Cataloghttps://www.cisa.gov/known-exploited-vulnerabilities-catalogVerified
- Microsoft SharePoint Security Advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38094Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would have constrained Warlock's lateral movement and reduced blast radius by implementing workload isolation and controlled network segmentation. The attack's ability to spread from SharePoint to 40+ hosts through SYSVOL shares would likely have been significantly limited.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Initial web shell deployment would likely have been contained to isolated SharePoint workloads, reducing the attack's ability to immediately access broader network resources and limiting the scope of initial compromise.
Control: Zero Trust Segmentation
Mitigation: Code execution within the SharePoint application pool would likely have remained isolated to designated workload segments, constraining the attacker's ability to escalate privileges beyond pre-defined security boundaries.
Control: East-West Traffic Security
Mitigation: Lateral movement through SYSVOL shares would likely have been constrained by east-west traffic controls, significantly reducing the attacker's ability to reach 40 hosts and limiting payload distribution across the domain infrastructure.
Control: Multicloud Visibility & Control
Mitigation: Command and control communications through VS Code tunnels would likely have been detected and constrained through multicloud visibility policies, limiting the attacker's ability to maintain persistent access and payload delivery.
Control: Egress Security & Policy Enforcement
Mitigation: Data exfiltration through cloud storage services would likely have been constrained by egress policies, limiting the attacker's ability to transfer sensitive data outside the controlled network perimeter.
Ransomware deployment would likely have been limited to isolated workload segments rather than affecting 33 hosts, reducing the overall impact scope and constraining the attacker's ability to disable security software across the entire infrastructure.
Impact at a Glance
Affected Business Functions
- Network Infrastructure Operations
- Government Digital Services
- Educational IT Systems
- Water Utility Control Systems
Estimated downtime: 18 days
Estimated loss: $2,500,000
Critical infrastructure operational data, government administrative records, university student and staff information, telecommunications customer data, and SharePoint farm configuration details including ASP.NET machine keys compromised across Portuguese and Spanish-speaking organizations.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to prevent lateral movement through SYSVOL shares and limit blast radius of SharePoint compromises
- • Deploy Egress Security & Policy Enforcement to block unauthorized outbound connections to suspicious cloud storage services like catbox.moe and wasabisys.com
- • Enable East-West Traffic Security monitoring to detect anomalous domain replication patterns and rapid payload distribution across multiple hosts
- • Implement Inline IPS (Suricata) with updated signatures to identify and block known SharePoint exploit patterns and malicious web shell deployment
- • Deploy Threat Detection & Anomaly Response capabilities to identify suspicious remote access tools like Visual Studio Code tunnels and BYOVD attacks using vulnerable drivers



