Symantec warns that the Warlock ransomware group is still breaking into unpatched on-premises SharePoint servers and has hit organisations in Spanish- and Portuguese-speaking countries, including in Europe. If your company runs SharePoint Server on its own servers, patch it, rotate the ASP.NET machine keys and hunt for web shells. SharePoint in Microsoft 365 is not affected.
Key facts
- Warlock, also known as Gold Salem, Longlegs and Storm-2603, emerged in 2025 with the ToolShell SharePoint zero-day chain: CVE-2025-49704, CVE-2025-49706, CVE-2025-53770 and CVE-2025-53771 (The Hacker News).
- Over the past two months, Symantec counts at least four victims: a water utility, a telecoms operator, a regional government body and a university (BleepingComputer).
- In one intrusion that began on 22 July 2026, a tool disabled antivirus/EDR on at least 40 machines in about two hours. The ransomware was then launched on at least 33 (SecurityWeek).
- To kill security tools they use the BYOVD technique with the K7RKScan.sys driver, vulnerable to CVE-2025-1055.
- The report comes a month after CISA warned of exploitation of six new SharePoint vulnerabilities (The Record).
Does this affect me if I use SharePoint in Microsoft 365?
No. The risk lies in SharePoint Server installed on your own servers (on-premises). According to Symantec and Carbon Black, Warlock combines older flaws such as ToolShell with more recent ones. That entry point remains viable on servers that are unpatched or unmitigated.
The victims are in Portuguese- and Spanish-speaking countries in Europe, Africa and Latin America (Dark Reading). Symantec doesn't know whether the focus is opportunistic, driven by exposed and vulnerable servers, or deliberate. For you it makes no difference: if you have an on-premises SharePoint reachable from the internet and behind on patches, you fit the profile.
Why isn't patching enough?
Because the attacker may already be inside. After getting in through SharePoint, Warlock drops web shells and steals the farm's ASP.NET machine keys. With them it forges signed payloads and gains remote code execution in the SharePoint application pool (BleepingComputer).
A patch closes the door. It doesn't invalidate keys that have already been taken. If your server was exposed while unpatched, you need to rotate keys and look for web shells.
How does it spread from one server to the whole network?
First it switches off the defences. Using a vulnerable driver (BYOVD), it disables antivirus and EDR across dozens of machines. Then it drops the ransomware into the domain's SYSVOL share so normal Active Directory replication spreads it across the network. To keep remote access, it abuses the Visual Studio Code tunnels feature (The Hacker News).
These are legitimate features used with bad intent. That's why they go unnoticed if nobody is watching.
What to do today
- Ask your IT provider whether you run SharePoint Server on-premises. If the answer is no, skip to step 5.
- Confirm that all SharePoint patches from 2025 and 2026 are applied and that the server isn't directly exposed to the internet.
- After patching, rotate the ASP.NET machine keys and search the server for web shells.
- Watch for new files being created in SYSVOL and for VS Code tunnels (code-insiders.exe running as a service). Set an alert for antivirus/EDR being disabled on several machines at once.
- Check that your backups are offline or immutable and that you have tested restoring them.
What it means for a small business
The fact that a 2025 flaw still works as an entry point the following autumn says a lot: there are servers nobody has patched. If you run SharePoint on-premises, the first question isn't technical. It's who looks after it and when it was last reviewed.
Our position is clear. An on-premises SharePoint facing the internet needs a named owner, up-to-date patches and a business reason to stay exposed. If there isn't one, take it off the internet.
Second, distrust the feeling of "it's patched". With stolen keys, the attacker doesn't need the vulnerability to come back. Patching without rotating keys or hunting for web shells leaves the job half done.
Third, your antivirus isn't the last line. In the 22 July case it was switched off on at least 40 machines in about two hours. What saves you then is finding out fast that it's being disabled, and having backups the ransomware can't touch.
If you're not sure which servers you expose or who maintains them, we can help you build that inventory through our cybersecurity service. If you don't use on-premises SharePoint, treat this as a reminder: every internet-facing server gets patched quickly.
Frequently asked questions
Am I safe if I use SharePoint in Microsoft 365?
This campaign targets SharePoint Server installed on your own servers, not SharePoint in Microsoft 365.
If I've already patched, am I done?
No. Warlock steals the ASP.NET machine keys and leaves web shells. After patching, rotate those keys and hunt for web shells.
Will my antivirus protect me?
Not on its own. Warlock disables it with a vulnerable driver. You need an alert when it's switched off on several machines, plus offline or immutable backups.
Sources
- The Hacker News – Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware
- BleepingComputer – Warlock ransomware breach SharePoint in water, telecom operator attacks
- SecurityWeek – Warlock Expands SharePoint Exploitation in Critical Infrastructure Attacks
- The Record – 'Warlock' ransomware used in attacks on critical infrastructure in Portuguese, Spanish-speaking countries
- Dark Reading – Warlock Ransomware Hits Large Spanish, Portuguese Orgs