Full Report
The suspected China-linked threat actor known as Warlock is still continuing to weaponize Microsoft SharePoint vulnerabilities, likely both old and new, in attacks targeting organizations in Portuguese- and Spanish-speaking countries. The activity, observed by the Symantec and Carbon Black Threat Hunter Team, has hit critical infrastructure, government, and education organizations. "In the
Analysis Summary
# Threat Actor: Warlock
## Attribution & Identity
* **Suspected Origin:** China-linked.
* **Aliases:** Gold Salem, Longlegs, Storm-2603.
* **Associated Clusters/Groups:** Overlaps with activity clusters known as CL-CRI-1040, CamoFei, and ChamelGang.
## Activity Summary
Warlock is an active threat group that has been prominent since mid-2025. Recent operations (mid-2026) show a sustained focus on weaponizing Microsoft SharePoint vulnerabilities to deploy ransomware. The group is notable for its speed; in one instance, they disabled security software on 40 hosts within two hours and deployed ransomware to 33 hosts shortly thereafter.
## Tactics, Techniques & Procedures
* **Initial Access:** Exploitation of Microsoft SharePoint Server vulnerabilities (e.g., "ToolShell" flaws and recent RCE zero-days) and unpatched SmarterMail instances.
* **Persistence & Web Shells:** Deployment of web shells to collect ASP.NET machine keys, allowing for the forgery of signed payloads and RCE within the SharePoint application pool.
* **Defense Evasion:**
* **BYOVD (Bring Your Own Vulnerable Driver):** Abusing legitimate-but-vulnerable drivers (e.g., `K7RKScan.sys` / CVE-2025-1055) to terminate security software.
* **DLL Side-loading:** Loading malicious code into memory to avoid detection.
* **Command & Control (C2) / Exfiltration:**
* Abuse of **Microsoft Visual Studio Code’s** built-in tunnel feature for remote access.
* Use of the legitimate DFIR tool **Velociraptor** for C2.
* Utilizing cloud storage services like **catbox[.]moe** and **wasabisys[.]com** for payload delivery.
* **Lateral Movement & Deployment:** Staging ransomware binaries in the domain's **SYSVOL share** to ensure ordinary domain replication delivers the malware to all machines.
* **Living-off-the-Land (LotL):** Heavy reliance on native tools for reconnaissance and command execution.
## Targeting
* **Sectors:** Critical infrastructure (Water utilities, Telecommunications), Government (regional bodies), and Education (universities).
* **Geography:** Portuguese- and Spanish-speaking countries across Europe, Africa, and Latin America.
* **Victims:** At least four organizations targeted in a recent two-month window, including a water utility, a telco provider, a regional government, and a university.
## Tools & Infrastructure
* **Malware:** Warlock Ransomware.
* **Legitimate Tools Abused:** Velociraptor, VS Code Tunnels.
* **Vulnerable Drivers:** `K7RKScan.sys`.
* **Infrastructure (Defanged):**
* catbox[.]moe
* wasabisys[.]com
## Implications
Warlock represents a significant threat to critical infrastructure due to their ability to rapidly pivot from vulnerability exploitation to full-scale ransomware deployment. Their use of "Identity Dark Matter" (forging machine keys) and legitimate tunneling tools (VS Code) makes them difficult to detect using traditional perimeter or file-based security solutions. The focus on specific linguistic regions suggests a targeted, rather than purely opportunistic, strategic intent.
## Mitigations
* **Patch Management:** Prioritize immediate patching of on-premises Microsoft SharePoint Servers, specifically addressing "ToolShell" and related RCE vulnerabilities.
* **Driver Blocklisting:** Implement Microsoft’s recommended driver blocklist to prevent Bring Your Own Vulnerable Driver (BYOVD) attacks, specifically targeting `K7RKScan.sys`.
* **Egress Monitoring:** Monitor or restrict outbound connections to known file-sharing sites (catbox, wasabisys) and unauthorized tunneling services like VS Code remote tunnels.
* **Hardening SharePoint:** Protect ASP.NET machine keys and monitor for unauthorized web shell uploads within SharePoint application directories.
* **SYSVOL Monitoring:** Implement alerts for unauthorized file additions or changes within the domain SYSVOL share, as this is used for rapid malware propagation.