News Room
16
Share
Warlock Ransomware Escalates Attacks on Critical Infrastructure via SharePoint Exploits
criticalThreat Intelligence

Warlock Ransomware Escalates Attacks on Critical Infrastructure via SharePoint Exploits

The China-nexus threat actor known as Warlock is actively exploiting critical Microsoft SharePoint vulnerabilities to cripple utilities and government sectors. Recent intelligence confirms the group is disabling endpoint protection and deploying ransomware across dozens of hosts within hours.

₿

Encrygma is selling the entire Full Cyber Weapon Research of Warlock Ransomware Escalates Attacks on Critical Infrastructure via SharePoint Exploits for ₿ 0.10 BTC. Contact us.

05 October 2026Last updated 05 October 20264 min readCheckpoint
E
Encrygma AI Cyber Weapons Advisory Services : ₿ 0.10 BTCWe sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram

Executive Takeaway — TL;DR

Category:
Threat Intelligence
Severity:
Critical
Actor Type:
APT
Geography:
Global
Confidence:
High Confidence
CVE:
CVE-2025-49704
Source:
Checkpoint
Read Time:
4 min

Executive Summary

As of October 5, 2026, threat intelligence reports have identified a significant escalation in ransomware operations by the actor group Warlock (tracked by some researchers as Longlegs or Storm-2603). The group is currently conducting a targeted campaign against critical infrastructure, specifically hitting utility providers, telecommunications, and government organizations. By leveraging persistent, high-impact vulnerabilities in Microsoft SharePoint, Warlock has demonstrated an ability to rapidly penetrate enterprise networks, neutralize defensive security measures, and achieve widespread data encryption and exfiltration.

Threat Analysis

The current campaign reflects Warlock’s evolving operational maturity. Following initial access through SharePoint servers—utilizing both known "ToolShell" vulnerabilities (CVE-2025-49704 and associated flaws) and newer, unpatched entry vectors—the threat actors move laterally with high velocity. The group’s modus operandi involves the rapid deployment of custom security-disabling tools. In one documented intrusion, the group successfully disabled endpoint protection on over 40 hosts within a two-hour window, followed by the deployment of Warlock ransomware across 33 systems.

Technical Details

Warlock’s attack chain is characterized by a high degree of automation post-compromise. Upon gaining initial foothold via SharePoint, the group stages its payload within the domain’s SYSVOL share. This allows for automated delivery to workstations and servers through standard domain replication, bypassing manual deployment requirements. The group utilizes a signed driver, K7RKScan, to forcibly disable security software. Additionally, researchers have observed the group abusing Visual Studio Code’s built-in tunneling features to maintain covert, persistent remote access to compromised networks.

Attribution Assessment

Attribution intelligence links Warlock to a China-nexus group. The group has shown a strategic preference for targets in Portuguese- and Spanish-speaking regions, including recent activities across Europe, Africa, and Latin America. Their continued reliance on SharePoint-based exploits suggests a specialized focus on common enterprise infrastructure to maintain a high ROI in their extortion-focused operations.

Implications

The operational footprint of this campaign indicates that organizations relying on legacy or unpatched SharePoint configurations are at immediate, critical risk. Because the group effectively uses domain replication for payload distribution, the speed of compromise leaves little time for standard incident response protocols to contain the threat once initial breach occurs.

Recommendations

  1. Patch Management: Immediately audit and apply security updates for all Microsoft SharePoint instances, specifically prioritizing CVE-2025-49704 and related vulnerabilities referenced in CISA advisories.
  2. Network Segmentation: Implement strict network segmentation to limit the reach of domain-level replication, particularly for the SYSVOL and NETLOGON shares.
  3. Endpoint Defense: Ensure EDR configurations are set to block the loading of untrusted or known-malicious drivers (such as K7RKScan) and monitor for unauthorized use of legitimate remote access tools like VS Code tunnels.
  4. Credential Hygiene: Rotate service account passwords associated with SharePoint and monitor for anomalous lateral movement in domain environments.
Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo