Security1 publisher2 min readPublished
Warlock ransomware operators keep breaking in through unpatched SharePoint, Symantec reports
China-linked Warlock operators hit at least four organisations through SharePoint flaws in two months, Symantec says. Its report lists six 2026 SharePoint CVEs only as possible additions, and the entry it documents is still older flaws on servers never patched or mitigated.
The Watch · Security desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- Symantec said the victims were two critical infrastructure operators, a water utility and a telecommunications provider, plus a regional government body and a university.
- After exploiting SharePoint, the group typically plants a webshell, exfiltrates ASP.NET machine keys and then deploys a forced signed payload for remote code execution.
- In one intrusion it disabled security software on at least 40 systems, then ran Warlock ransomware on at least 33 of them.
- The group stages the Warlock payload in the domain's SYSVOL share, which replicates to every domain controller and is readable across the domain.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure Machine keys are copied before code runs, so a SharePoint server patched after that step still has keys the group holds until they are rotated. Patch status alone does not show a farm is clean.
- constraint Patch teams cannot use this report to rank the six 2026 SharePoint flaws by observed Warlock abuse. Ordering those fixes will need exploitation evidence from somewhere else.
- capability A payload in SYSVOL reaches every domain controller through normal replication, so once the group can write there, a single SharePoint foothold can end in encryption across the whole domain.
- precedent The group has been reusing the same entry point for more than a year, so any SharePoint deployment left unpatched or unmitigated stays a candidate for its next round of victims, in any region.
Symantec hedges its wording on the newer flaws. Storm-2603's arsenal "may also include" CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, CVE-2026-58644, CVE-2026-50522 and CVE-2026-55040, according to SecurityWeek's account of the report [6]. That account does not tie any of the six to one of the four recent intrusions [1].
The route Symantec does document is older. "Longlegs' continued activity, more than a year after Warlock ransomware first came to prominence, shows that exploitation of ToolShell and other related SharePoint vulnerabilities remains a viable initial access route for attackers on SharePoint deployments that have not been patched or otherwise mitigated," Symantec wrote [14].
Last year, the Chinese state-sponsored groups Linen Typhoon and Violet Typhoon were seen exploiting the two SharePoint flaws known as ToolShell as zero-days, at least two weeks before public disclosure [3]. Within weeks, more than 400 SharePoint servers were compromised. Storm-2603's exploitation stood out amid heavy APT activity [4]. By October 2025, researchers had tied numerous Warlock attacks to ToolShell. The victims included a Middle East telecom firm, African and South American government entities and a US university [5].
The victim types have held for a year while the geography moved. Telecoms, government bodies and universities appear in both the 2025 set and the latest four [2]. The new intrusions were in Portuguese- and Spanish-speaking countries [7]. SecurityWeek reports that Warlock is believed to be run by a China-based group tracked as Longlegs and Storm-2603, which has been linked to CL-CRI-1040, CamoFei and ChamelGang [2].
Past the SharePoint stage, the group runs code in memory through DLL sideloading. It pulls more payloads from legitimate file-sharing and storage services, loads a vulnerable driver to disable security tools, and uses living-off-the-land tools for reconnaissance and command execution [11]. Its remote access is made to look like administrator traffic. "The group has also been observed abusing Visual Studio Code's built-in tunnel feature, installing the code-insiders.exe binary as a service to establish covert remote network access that blends into traffic that typically originates from developer or administrator workstations," Symantec wrote [12]. The specific artifact is code-insiders.exe running as a service [12].
What to watch
- Symantec or another responder publishing indicators that tie one of the six 2026 SharePoint CVEs to a specific Warlock intrusion, moving it from possible to observed.
- Further Warlock victims in Portuguese- and Spanish-speaking countries, or a return to the Middle East, African, South American and US targets seen in 2025.