The Warlock ransomware group continues to breach critical infrastructure, government and education organizations by exploiting SharePoint vulnerabilities, according to a Symantec report covered by SecurityWeek. The finding matters because the same flaws have remained a viable initial access route for more than a year, and the group is now hitting utilities and telecom providers in Portuguese- and Spanish-speaking countries.
Symantec attributes Warlock to a China-based hacking group tracked as Longlegs and Storm-2603, which has been linked to operations including CL-CRI-1040, CamoFei and ChamelGang. BleepingComputer reports the gang emerged in June 2025 and gained notoriety a month later after exploiting a chain of SharePoint zero-days known as ToolShell, tracked as CVE-2025-49704, CVE-2025-49706, CVE-2025-53770 and CVE-2025-53771. By August, Microsoft observed state-backed groups Linen Typhoon and Violet Typhoon using ToolShell exploits, along with Storm-2603. Within weeks, more than 400 SharePoint servers were compromised, and by October 2025 researchers uncovered numerous Warlock attacks exploiting ToolShell. Victims included a Middle East telecom firm, African and South American government entities and a US university.
In its new report, Symantec says Storm-2603 continues to favor SharePoint exploitation. Beyond ToolShell, its arsenal may include recent flaws tracked as CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, CVE-2026-58644, CVE-2026-50522 and CVE-2026-55040. Over the past two months, the operator hit at least four victim organizations in Portuguese- and Spanish-speaking countries. “The victims included two critical infrastructure operators, a water utility and a telecommunications provider, along with a regional government body and a university,” Symantec reports. BleepingComputer adds that the focus appears to span Europe, Africa and Latin America.
In one intrusion that began on July 22, the group deployed a tool that disabled security software on at least 40 systems within about two hours, then executed Warlock on at least 33 of them, according to Symantec and Carbon Black researchers cited by BleepingComputer. The final stage occurred on July 31, with Warlock appearing almost as soon as protection was disabled on each host. The AV/EDR-killing tool was deployed via the bring your own vulnerable driver technique using a signed K7RKScan driver vulnerable to CVE-2025-1055. Two days after initial access, the attacker conducted reconnaissance and deleted what appeared to be staging artifacts.
Symantec describes a consistent post-exploitation pattern: SharePoint exploitation is typically followed by webshell deployment, ASP.NET machine key exfiltration and a forced signed payload for remote code execution. Storm-2603 relies on DLL sideloading for in-memory code execution, drops additional payloads from legitimate file-sharing and storage services, and uses living-off-the-land tools for reconnaissance and command execution. The group also abuses Visual Studio Code’s built-in tunnel feature, installing the code-insiders.exe binary as a service to establish covert remote access that blends into developer or administrator traffic, Symantec notes. BleepingComputer reports that researchers found the open-source penetration testing framework NetExec on one system, used for Active Directory enumeration, credential spraying and remote command execution.
The Warlock payload is staged inside the domain’s SYSVOL share, which is automatically replicated to every domain controller and readable domain-wide, allowing the file-encrypting ransomware to execute at scale. Symantec notes that Longlegs’ continued activity more than a year after Warlock first came to prominence shows exploitation of ToolShell and related SharePoint vulnerabilities remains a viable initial access route for attackers on deployments that have not been patched or otherwise mitigated. What remains unconfirmed is the full scope of the recent campaign: Symantec identifies at least four victim organizations over two months, but no total victim count, ransom figures or data-theft volumes have been published. The report also does not establish whether the six newer CVEs listed as possible arsenal additions were actually exploited in these intrusions.
