Warlock Ransomware Targets Unpatched SharePoint Servers

The suspected China-linked Warlock ransomware group is exploiting Microsoft SharePoint vulnerabilities to attack critical infrastructure, government, and education organizations across Portuguese- and Spanish-speaking regions. After compromising on-premises SharePoint servers, attackers deploy web shells, steal ASP.NET machine keys, and forge signed payloads to gain remote code execution. Warlock also abuses vulnerable drivers and legitimate tools to disable security software, establish remote access, and distribute ransomware through SYSVOL, reaching dozens of hosts within hours. Organizations should urgently patch SharePoint, investigate exposed servers for web shells, and monitor for suspicious driver loading, VS Code tunnels, and SYSVOL activity.

Reference: thehackernews.com