Vulnerabilities & Exploits · Ransomware

Warlock Keeps SharePoint as a Ransomware Doorway

Symantec says Warlock, the China-nexus group also tracked as Longlegs and Storm-2603, kept abusing Microsoft SharePoint Server in the past two months, hitting at least four organizations in Portuguese- and Spanish-speaking countries. The victims included a water utility, a telecom provider, a regional government body, and a university.

The group’s playbook starts with SharePoint bugs, including the 2025 ToolShell flaws and newer CVEs, then moves into the Windows domain. Symantec says one intrusion used a tool to disable security software on at least 40 hosts, then staged Warlock in the domain’s SYSVOL share, which Windows replicates automatically, so the ransomware reached at least 33 systems without hand-copying it everywhere.

That makes the SharePoint server a launch point, not the end of the incident. If on-prem SharePoint sits inside the same domain as file shares and workstations, a single internet-facing foothold can turn into domain-wide ransomware spread and security-tool disablement.

3 sources · 4h ago

CVEs in this update

10 CVEs

Across Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition.

4 critical · 2 high · 4 medium · 0 low

9 in CISA KEV · 5 with EPSS above 1%

4 with functional or packaged public exploit code

Highest severity: CVE-2025-53770 · 9.8 CRITICAL

Highest EPSS: CVE-2025-53770 · 100%

Timeline

Sources

Vendor digest: Microsoft

Part of the PlainSec briefing for 2026-10-02

Every edition of this story: Warlock Keeps SharePoint as a Ransomware Doorway

More from today