hacker-news · Crawled Oct 3, 2026

Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware

2 IoCs 2 Actors 1 Malware
Read original article ↗

AI Summary

The China-linked threat actor Warlock, also known as Longlegs or Gold Salem, is actively exploiting vulnerabilities in on-premises Microsoft SharePoint Server deployments to gain initial access, deploy web shells, and achieve remote code execution. The group targets organizations in Portuguese- and Spanish-speaking countries, including critical infrastructure, government, and education sectors. After gaining access, Warlock uses DLL sideloading, legitimate cloud storage services for payload delivery, and the BYOVD technique with a vulnerable driver to disable security tools. The attackers then deploy ransomware at scale by staging payloads in the SYSVOL share and leveraging living-off-the-land techniques such as VS Code tunnels for persistence and lateral movement.

AI-extracted · verify before operational use

Extracted Entities 3 found

Indicators of Compromise 2 extracted

Type Value Detail
Domain catbox[.]moe Details →
Domain wasabisys[.]com Details →

MITRE ATT&CK TTPs 38 techniques

T1018 Remote System Discovery · Discovery T1021.001 Remote Desktop Protocol · Lateral Movement T1021.004 SSH · Lateral Movement T1048 Exfiltration Over Alternative Protocol · Exfiltration T1053 Scheduled Task/Job · Execution T1055.001 Dynamic-link Library Injection · Defense Evasion T1059.001 PowerShell · Execution T1070 Indicator Removal · Defense Evasion T1071.001 Web Protocols · Command And Control T1078 Valid Accounts · Defense Evasion T1082 System Information Discovery · Discovery T1083 File and Directory Discovery · Discovery T1087 Account Discovery · Discovery T1102 Web Service · Command And Control T1105 Ingress Tool Transfer · Command And Control T1110.003 Password Spraying · Credential Access T1111 Multi-Factor Authentication Interception · Credential Access T1133 External Remote Services · Persistence T1190 Exploit Public-Facing Application · Initial Access T1204.001 Malicious Link · Execution T1218.001 Compiled HTML File · Defense Evasion T1219 Remote Access Software · Command And Control T1484 Domain or Tenant Policy Modification · Defense Evasion T1485 Data Destruction · Impact T1486 Data Encrypted for Impact · Impact T1526 Cloud Service Discovery · Discovery T1534 Internal Spearphishing · Lateral Movement T1564.008 Email Hiding Rules · Defense Evasion T1566 Phishing · Initial Access T1567 Exfiltration Over Web Service · Exfiltration T1572 Protocol Tunneling · Command And Control T1621 Multi-Factor Authentication Request Generation · Credential Access T1663 T1663 T1687 T1687 T1003.001 LSASS Memory · Credential Access T1087.002 Domain Account · Discovery T1210 Exploitation of Remote Services · Lateral Movement T1558 Steal or Forge Kerberos Tickets · Credential Access