A China-linked ransomware group called Warlock is actively exploiting Microsoft SharePoint vulnerabilities to breach critical infrastructure organizations across multiple continents, according to a new report from Symantec’s Threat Hunter Team published on October 3.
Warlock, also tracked as Gold Salem, Longlegs, and Storm-2603 by Microsoft, first surfaced on the Russian-language RAMP forum in June 2025. Since then, the group has rapidly expanded its victim list. In the past two months alone, it has compromised at least four organizations across Portuguese- and Spanish-speaking nations in Europe, Africa, and Latin America. One single intrusion affected more than 40 hosts.
The attack chain begins with unpatched SharePoint servers. Warlock deploys web shells to gain initial access, then harvests the SharePoint farm’s ASP.NET machine keys. With those keys, the group forges signed payloads that grant full remote code execution. From there, it moves laterally across networks using SMB and RDP protocols.
For defense evasion, Warlock uses a Bring Your Own Vulnerable Driver (BYOVD) technique. It exploits the K7RKScan.sys driver (CVE-2025-1055) to disable security software on target machines. The group also disguises its tools behind legitimate names. For example, it renames the RClone data exfiltration tool as “TrendSecurity.exe” and uses Proton Drive with burner credentials for cloud-based data theft.
“In one intrusion against a critical infrastructure operator, the attackers pushed a tool designed to disable security software to at least 40 hosts within about two hours, then deployed Warlock on at least 33 hosts by staging it in the domain’s SYSVOL share, where ordinary domain replication delivered it to machines,” the researchers said.
Persistence is equally sophisticated. A script called “TakeOver.bat” automates backdoor creation by activating the built-in guest account, adding it to the Administrators group, and installing scheduled tasks. Even after defenders attempt remediation, the group deploys Group Policy Objects named “TakeOver” to reinstate those backdoor accounts.
The ransomware itself is a customized derivative of the leaked LockBit 3.0 builder, according to both Trend Micro and Symantec. Encrypted files receive the “.x2anylock” extension. Victims have included a water utility, a telecommunications provider, a regional government, and a university.
Microsoft first attributed Warlock distribution to the Chinese threat actor Storm-2603 in July 2025. Since then, the group has also claimed responsibility for attacking UK telecoms firm Colt Technology Services.
Organizations running SharePoint servers should prioritize patching all known vulnerabilities and audit ASP.NET machine key exposure to reduce their attack surface.

