The breach isn’t the problem. The spread is. →Free Assessment

Executive Summary

The China-linked threat actor Warlock (also known as Gold Salem, Longlegs, and Storm-2603) continues to exploit Microsoft SharePoint vulnerabilities to deploy ransomware against critical infrastructure organizations in Portuguese and Spanish-speaking countries. In recent attacks observed through October 2026, Warlock targeted water utilities, telecommunications providers, government bodies, and universities across Europe, Africa, and Latin America. The group leverages web shells to extract SharePoint farm ASP.NET machine keys, uses legitimate tools like Velociraptor for command-and-control, and employs bring-your-own-vulnerable-driver techniques to disable security software before deploying ransomware at scale through domain SYSVOL shares.

This incident highlights the persistent threat of unpatched SharePoint deployments and the evolving sophistication of state-sponsored ransomware operations targeting critical infrastructure sectors globally.

Why This Matters Now

Warlock's continued exploitation of SharePoint vulnerabilities over 15 months demonstrates that critical infrastructure organizations remain vulnerable to sophisticated nation-state ransomware attacks, with recent targeting of water utilities and telecommunications providers showing escalating risks to essential services.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Warlock extracts SharePoint farm ASP.NET machine keys to forge validly signed payloads, uses legitimate tools to evade detection, and disables security software before deploying ransomware at enterprise scale through domain replication.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would have constrained Warlock's lateral movement and reduced blast radius by implementing workload isolation and controlled network segmentation. The attack's ability to spread from SharePoint to 40+ hosts through SYSVOL shares would likely have been significantly limited.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Initial web shell deployment would likely have been contained to isolated SharePoint workloads, reducing the attack's ability to immediately access broader network resources and limiting the scope of initial compromise.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Code execution within the SharePoint application pool would likely have remained isolated to designated workload segments, constraining the attacker's ability to escalate privileges beyond pre-defined security boundaries.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Lateral movement through SYSVOL shares would likely have been constrained by east-west traffic controls, significantly reducing the attacker's ability to reach 40 hosts and limiting payload distribution across the domain infrastructure.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Command and control communications through VS Code tunnels would likely have been detected and constrained through multicloud visibility policies, limiting the attacker's ability to maintain persistent access and payload delivery.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Data exfiltration through cloud storage services would likely have been constrained by egress policies, limiting the attacker's ability to transfer sensitive data outside the controlled network perimeter.

Impact (Mitigations)

Ransomware deployment would likely have been limited to isolated workload segments rather than affecting 33 hosts, reducing the overall impact scope and constraining the attacker's ability to disable security software across the entire infrastructure.

Impact at a Glance

Affected Business Functions

  • Network Infrastructure Operations
  • Government Digital Services
  • Educational IT Systems
  • Water Utility Control Systems
Operational Disruption

Estimated downtime: 18 days

Financial Impact

Estimated loss: $2,500,000

Data Exposure

Critical infrastructure operational data, government administrative records, university student and staff information, telecommunications customer data, and SharePoint farm configuration details including ASP.NET machine keys compromised across Portuguese and Spanish-speaking organizations.

Recommended Actions

  • • Implement Zero Trust Segmentation to prevent lateral movement through SYSVOL shares and limit blast radius of SharePoint compromises
  • • Deploy Egress Security & Policy Enforcement to block unauthorized outbound connections to suspicious cloud storage services like catbox.moe and wasabisys.com
  • • Enable East-West Traffic Security monitoring to detect anomalous domain replication patterns and rapid payload distribution across multiple hosts
  • • Implement Inline IPS (Suricata) with updated signatures to identify and block known SharePoint exploit patterns and malicious web shell deployment
  • • Deploy Threat Detection & Anomaly Response capabilities to identify suspicious remote access tools like Visual Studio Code tunnels and BYOVD attacks using vulnerable drivers

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image