The suspected China-linked threat actor Warlock — also tracked as Gold Salem, Longlegs and Storm-2603 — continues to weaponise on-premises Microsoft SharePoint vulnerabilities against critical infrastructure, government and education organisations. Symantec and the Carbon Black Threat Hunter Team reported on 3 October 2026 that over the past two months the group hit at least four organisations in Portuguese- and Spanish-speaking countries across Europe, Africa and Latin America, including a water utility, a telecommunications provider, a regional government body and a university.
Warlock rose to prominence in mid-2025 when it was tied to zero-day exploitation of the "ToolShell" SharePoint flaws to deploy ransomware. Since then the actor has been linked to compromising SmarterTools via an unpatched SmarterMail instance, using legitimate tools such as Velociraptor for command-and-control, and BYOVD (bring your own vulnerable driver — loading a vulnerable driver to disable security products). Overlaps exist with older clusters CL-CRI-1040, CamoFei and ChamelGang.
In one intrusion against a critical-infrastructure operator, Symantec said attackers pushed a security-disabling tool to at least 40 hosts within about two hours, then deployed Warlock on at least 33 hosts by staging it in the domain’s SYSVOL share so ordinary domain replication delivered the payload. The chain often starts with SharePoint Server flaws on-prem: after initial access, web shells capable of targeting multiple SharePoint versions drop, steal the farm’s ASP.NET machine keys and forge validly signed payloads for code execution inside the SharePoint application pool.
Other observed tactics include DLL sideloading to load malicious code into memory; downloading follow-on payloads from legitimate cloud storage such as catbox.moe and wasabisys.com to blend with normal traffic; abusing the legitimate-but-vulnerable driver K7RKScan.sys (CVE-2025-1055) in BYOVD attacks — the same driver previously exploited by DragonForce ransomware actors; living-off-the-land reconnaissance; and abusing Visual Studio Code’s built-in tunnel feature for remote access. As recently as 22 July 2026 the actors reportedly went from a SharePoint web shell through discovery, code execution, VS Code tunnels, security-tool termination and ransomware binary deployment in one chain.
Symantec stresses that more than a year after Warlock’s rise, ToolShell and related SharePoint flaws remain a viable initial-access route against unpatched or poorly mitigated deployments. The apparent focus on Portuguese- and Spanish-speaking countries may be opportunistic (exposed servers) or more deliberate tasking. For Nordic readers the lesson is not that "it happens elsewhere" but that internet-exposed on-prem SharePoint with delayed patching is the same attack surface regardless of language — and that ransomware actors who also disable EDR across dozens of hosts in two hours demand both patch discipline and detection of SYSVOL staging plus unusual VS Code tunnels.
SharePoint remains widely used in Nordic municipalities, energy companies and healthcare organisations as intranet and document hubs. Once machine keys are stolen, attackers can forge ViewState and regain code execution even after a single web shell is cleaned, unless keys are rotated. Incident response is therefore more than "delete the aspx file": farm secrets, service accounts and connected file servers must be reviewed. Warlock’s speed — dozens of hosts in two hours — leaves little room for manual ticket handling without prepared playbooks.
Concrete steps for IT and security leads
Inventory all on-prem SharePoint Server installs; patch ToolShell and follow-on advisories, or put exposed servers behind VPN/Zero Trust. Hunt for web shells under the SharePoint tree, unexpected machine-key reads, SYSVOL writes of unknown binaries, K7RKScan.sys loads and VS Code tunnels from servers. Segment critical infrastructure so a compromised collaboration server cannot reach OT/SCADA or domain controllers without strong controls. Rehearse recovery from offline backups ransomware cannot touch. Rotate ASP.NET machine keys after suspected compromise and review domain GPO/SYSVOL for unexpected payloads.