The suspected China-linked threat actor known as Warlock is continuing to aggressively weaponize Microsoft SharePoint vulnerabilities, exploiting both legacy security flaws and newly uncovered zero-days in a sustained campaign targeting organizations across Portuguese- and Spanish-speaking countries.
Recent telemetry from the Symantec and Carbon Black Threat Hunter Team has brought to light a targeted wave of intrusions impacting high-stakes sectors, including critical infrastructure operators, regional government bodies, and higher education institutions. The malicious activity underscores the ongoing dangers posed by unpatched enterprise software and highlights the relentless operational tempo of state-backed and financially motivated cybercrime syndicates.
According to the Broadcom-owned cybersecurity unit, the threat group—which is also tracked across the intelligence community under various monikers such as Gold Salem, Longlegs, and Storm-2603—has struck multiple high-value targets over a compressed two-month window. Among the identified victims are critical infrastructure entities such as a municipal water utility and a major telecommunications provider, alongside a regional government organization and a university. Geographically, these attacks have concentrated on nations spanning Europe, Africa, and Latin America where Portuguese and Spanish are spoken, raising questions regarding whether the geographic focus stems from opportunistic scanning of exposed infrastructure or a deliberate, directed operational mandate.
Warlock first rose to widespread prominence in mid-2025, capturing the attention of global security analysts when it leveraged zero-day exploits targeting the "ToolShell" SharePoint vulnerabilities to deploy devastating ransomware payloads onto compromised corporate networks. Over the subsequent months, the group has steadily expanded its operational footprint and refinement of tactics. Earlier this year, security researchers linked the syndicate to the sophisticated compromise of SmarterTools infrastructure through the exploitation of an unpatched SmarterMail instance. Furthermore, the group has frequently incorporated legitimate administration and forensic utilities into its attack chains, leveraging tools like Velociraptor for command-and-control communications while utilizing the "bring your own vulnerable driver" (BYOVD) technique to systematically disarm and neutralize host-based security software before deploying its encryption routines.

Threat intelligence analysis conducted by Symantec indicates that Warlock shares distinct technical and infrastructural overlaps with older, established activity clusters previously designated as CL-CRI-1040, CamoFei, and ChamelGang, suggesting a lineage of shared codebases or personnel within the broader regional threat landscape.
The mechanics of Warlock’s SharePoint intrusions reveal a high degree of operational efficiency and tactical stealth. The attacks typically commence with the exploitation of multiple known and emerging vulnerabilities affecting on-premises Microsoft SharePoint Server deployments. Once the threat actors successfully establish a foothold within the perimeter, they deploy custom web shells engineered to operate across multiple versions of the SharePoint platform.
The primary objective of these deployed web shells is the surreptitious collection of the SharePoint farm’s sensitive ASP.NET machine keys. Armed with these cryptographic keys, the attackers possess the capability to forge validly signed payloads, effectively bypassing standard authentication mechanisms and achieving high-privileged remote code execution directly inside the SharePoint application pool.
Security researchers have documented rapid, destructive operational phases following initial access. In one notable intrusion targeting a critical infrastructure operator, investigators observed the threat actors pushing a specialized utility designed to disable endpoint security software across at least 40 individual hosts within a mere two-hour window. Following the neutralization of local defenses, the attackers deployed the Warlock ransomware binary to at least 33 hosts by cleverly staging the malicious payload within the domain’s SYSVOL share. This technique exploited standard domain replication mechanisms, forcing the network itself to quietly distribute the ransomware binaries to connected machines without requiring further manual intervention from the operators.

Detailed timelines of recent incident response telemetry indicate that as recently as late July 2026, the group was actively exploiting SharePoint Server flaws to drop persistent web shells, conduct internal network discovery, secure arbitrary code execution inside application pools, and roll out secondary payloads designed to burrow deeper into enterprise architectures. During these advanced phases, the threat actors have been observed establishing persistent Visual Studio Code tunnels, terminating active security processes, and ultimately triggering the deployment of the ransomware binary to paralyze victim operations.
The sustained activity of the Longlegs cluster, occurring more than a year after Warlock first emerged onto the global threat landscape, serves as a stark reminder that legacy vulnerabilities and unpatched ToolShell flaws remain highly viable and profitable initial access pathways for determined adversaries. Organizations utilizing on-premises enterprise collaboration platforms continue to face significant risks in the absence of rigorous patch management and proactive defensive monitoring. As threat actors continue to refine their evasion techniques, integrate dual-use administrative tooling, and leverage native administrative protocols like SYSVOL replication for payload delivery, defenders must maintain heightened vigilance across all externally facing enterprise assets.
