Security researchers identify the Warlock ransomware group as a China-based operator that exploits SharePoint zero-day vulnerabilities to target critical infrastructure globally.

The Warlock ransomware group is believed to be operated by a China-based hacking group. Storm-2603 has been linked to malicious operations including CL-CRI-1040, CamoFei, and ChamelGang.

Warlock surfaced in the summer of 2025. By October 2025, researchers uncovered numerous Warlock ransomware attacks that exploited ToolShell. Warlock victims have included a Middle East telecom firm, African and South American government entities, and a US university. Earlier Warlock campaigns targeted organizations in Brazil, India, Japan, Russia, Taiwan, and the United States.

Recent Warlock victims included two critical infrastructure operators, a water utility, a telecommunications provider, a regional government body, and a university. Over the past two months, the Warlock operator has attacked at least four victim organizations in Portuguese- and Spanish-speaking countries. The U.S. National Nuclear Security Administration (NNSA) was breached via SharePoint vulnerabilities in July 2025. Warlock’s 2025 attacks included telecom firms Colt and Orange, as well as a U.S. university, with the group leveraging SharePoint vulnerabilities to deploy ransomware after disabling security software on 40+ systems in a single intrusion.

In one intrusion, the hacking group deployed a tool to disable security software on at least 40 systems. In the same intrusion, the group executed Warlock ransomware on at least 33 systems, according to reporting from SecurityWeek.

Warlock's exploitation of SharePoint flaws is typically followed by webshell deployment, ASP.NET machine key exfiltration, and the deployment of a force-signed payload for remote code execution. Storm-2603 relies on DLL sideloading for in-memory code execution. Storm-2603 drops additional payloads from legitimate file-sharing and storage services.

Storm-2603 uses a vulnerable driver to disable security tools. Storm-2603 relies on living-off-the-land tools for reconnaissance and command execution.

The threat actor stages the Warlock payload inside the domain’s SYSVOL share to execute the ransomware at scale. The SYSVOL share is automatically replicated to every domain controller and is readable domain-wide. Storm-2603, linked to Warlock, has been using the SYSVOL share to stage ransomware payloads for mass deployment across victim networks, a technique that leverages Active Directory replication to distribute malware efficiently.

Warlock's arsenal may include recent flaws such as CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, CVE-2026-58644, CVE-2026-50522, and CVE-2026-55040. The group's arsenal includes multiple recent SharePoint vulnerabilities, as noted in a Symantec report published in late 2026, indicating the group's continued use of evolving exploit techniques.

The Cybersecurity and Infrastructure Security Agency added a handful of SharePoint vulnerabilities to its Known Exploited Vulnerabilities catalog over the summer of 2026. Dick O'Brien is a principal intelligence analyst for the Symantec Threat Hunter Team.

"Longlegs’ continued activity, more than a year after Warlock ransomware first came to prominence, shows that exploitation of ToolShell and other related SharePoint vulnerabilities remains a viable initial access route for attackers on SharePoint deployments that have not been patched or otherwise mitigated," Symantec said.

Why It Matters

The identification of Warlock as a China-based operator linking ransomware crime to state-sponsored tactics raises the stakes for global critical infrastructure protection. The group’s use of SharePoint zero-days, which affected over 400 servers and 148 organizations within weeks in 2025, demonstrates how unpatched enterprise software can serve as a gateway for widespread disruption. The inclusion of vulnerabilities in the CISA Known Exploited Vulnerabilities catalog in summer 2026 reflects ongoing regulatory attention to these persistent threats.

Technical overlaps between Warlock and Chinese APT groups, as identified by Halcyon’s Ransomware Research Center and Palo Alto Networks’ Unit 42, suggest potential collaboration or shared resources between financially motivated criminals and state-backed actors. This convergence complicates attribution and defense strategies, as seen in the group’s use of tools like Visual Studio Code tunnels and SYSVOL shares to evade detection and scale attacks. The continued viability of ToolShell exploits more than a year after their discovery reflects the challenge of securing legacy systems against advanced persistent threats.

Timeline

Warlock surfaced in the summer of 2025.

APT27 and APT31 were among the threat actors exploiting SharePoint zero-days in July 2025. ESET data shows the United States accounted for 13% of ToolShell attacks globally, making it the most targeted country, with attacks detected in Germany on July 17, 2025, and Italy on July 18, 2025. As recently as July 22, 2026, the threat actors are said to have exploited SharePoint Server flaws to drop a web shell, conduct discovery, obtain arbitrary code execution inside the SharePoint application pool, deploy additional payloads, burrow deeper into the network, establish VS Code tunnels, terminate security software, and ultimately deploy the ransomware binary.

What's New

Over 400 SharePoint servers were compromised within weeks of the initial ToolShell zero-day exploitation in July 2025, according to an analysis of reports on the attack patterns linked to Storm-2603 and other Chinese state-sponsored groups.

In 2025, Chinese state-sponsored groups Linen Typhoon and Violet Typhoon exploited ToolShell zero-days two weeks before public disclosure, a tactic later adopted by Storm-2603 (Warlock), according to reports. Warlock ransomware emerged in June 2025 and claimed 16 attacks in its first month, reaching 60+ victims by September 2025, with 400+ SharePoint servers across 148 organizations compromised within weeks of the ToolShell zero-day exploitation.