Warlock Expands SharePoint Exploitation in Critical Infrastructure Attacks

Warlock Expands SharePoint Exploitation in Critical Infrastructure Attacks
Warlock ransomware, linked to the China-based Longlegs and Storm-2603 cluster, continues to exploit SharePoint vulnerabilities to breach critical infrastructure, government, and education targets. Recent attacks have affected victims across multiple regions, with the group using webshells, payload staging, and security tool tampering to enable large-scale encryption. #Warlock #Longlegs #Storm2603 #SharePoint #ToolShell

Keypoints

  • Warlock keeps targeting SharePoint servers in high-value organizations.
  • Storm-2603 is linked to the China-based Longlegs hacking group.
  • ToolShell exploitation has been a major initial access route.
  • The attackers disable security tools and deploy Warlock across many systems.
  • The group also uses DLL sideloading, webshells, and Visual Studio Code tunnels.

Read More: https://www.securityweek.com/warlock-expands-sharepoint-exploitation-in-critical-infrastructure-attacks/