The Warlock group continues to exploit vulnerabilities in SharePoint Server to infiltrate corporate networks, according to a new analysis from Symantec . Researchers document at least four organizations that have been attacked in the past two months, including two critical infrastructure providers.

The targets included a water company, a telecommunications provider, a regional government agency and a university. Symantec says the organizations were located in Portuguese- and Spanish-speaking countries in Europe, Africa and Latin America, without naming victims or countries. This information is also reported by BleepingComputer.
Symantec tracks the group as Longlegs and also links it to Storm-2603. Its connection to China is described as a researcher's estimate and not publicly confirmed.
How vulnerabilities in SharePoint Server are exploited
According to Symantec, attackers are exploiting vulnerabilities in locally installed SharePoint. In one analyzed attack, researchers detected the first malicious action on July 22, 2026: an ASPX file was placed in the SharePoint layout folder.
The malicious web shell allows remote command execution and, according to the research, is designed to work on multiple versions of the software. Its goal was to collect the installation's ASP.NET keys. With these, the attackers could create a digitally signed payload that executed code inside the SharePoint application process.

Symantec then documented network reconnaissance tools, lateral movement, and abuse of Visual Studio Code Insiders tunneling for remote access. At a later stage, the attackers used NetExec for Active Directory mapping, password testing across multiple accounts, and remote command execution.
The same research describes a tool that disabled security software on at least 40 systems in about two hours. The researchers then found the Warlock ransomware on at least 33 computers. The incident shows how quickly a server breach can spread across an entire network.
In some Longlegs attacks, researchers have also observed abuse of a signed but vulnerable K7RKScan driver to terminate security processes at the kernel level. Symantec does not confirm that the same driver was used in the incident involving the 40 systems.
See also: CVE-2026-45659: SharePoint vulnerability listed in CISA's KEV
Why SharePoint Server remains a target
The tactic starts with a vulnerable SharePoint Server installation and continues with the use of legitimate tools, making it difficult to detect. Symantec says the ransomware files were stored in the shared SYSVOL folder, which is synchronized between domain controllers. This means the files reached multiple computers without being transferred to each one separately.
The recent geographic concentration of victims does not in itself prove a targeted campaign against specific countries. Symantec believes it could be due to either the exposure of vulnerable servers to the internet or a more targeted selection of victims, without reaching a definitive conclusion.

Protection measures and checks after a possible breach
CISA has separately warned of active exploitation of three vulnerabilities in on-premises SharePoint servers: CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164. The warning does not attribute these specific attacks to the Warlock group. The agency recommends installing the latest Microsoft updates and verifying that they have been applied to all servers.
The same warning recommends enabling AMSI for each SharePoint application and full request body scanning where possible. Organizations should limit direct exposure of servers to the internet and block external access to central management.
See also: Qilin and Warlock ransomware: Using vulnerable drivers to disable EDR
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
In the event of a potential breach, administrators should first look for malicious files and ASP.NET key harvesters and then consider changing the keys. CISA warns that changing without first eliminating the exploits could allow attackers to reacquire the new keys. Useful checks include unusual requests, suspicious SharePoint processes, and unknown web files.
See also: Out-of-date SharePoint servers open the door to attacks
The analysis does not name recent targets or confirm any individual steps as common across all attacks. However, the group's persistence in vulnerable SharePoint Server makes it critical to promptly apply updates and check for signs of compromise across the entire network.
