Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware
AI Summary
The China-linked threat actor Warlock, also known as Longlegs or Gold Salem, is actively exploiting vulnerabilities in on-premises Microsoft SharePoint Server deployments to gain initial access, deploy web shells, and achieve remote code execution. The group targets organizations in Portuguese- and Spanish-speaking countries, including critical infrastructure, government, and education sectors. After gaining access, Warlock uses DLL sideloading, legitimate cloud storage services for payload delivery, and the BYOVD technique with a vulnerable driver to disable security tools. The attackers then deploy ransomware at scale by staging payloads in the SYSVOL share and leveraging living-off-the-land techniques such as VS Code tunnels for persistence and lateral movement.
AI-extracted · verify before operational use