AI Weekly Malaysia

Back to items Summaries

Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware

ID
31487
Status
summarized
Published
03 Oct 2026, 10:36 PM
Fetched
04 Oct 2026, 12:16 AM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/10/warlock-exploits-sharepoint-flaws-to.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
3.5
Created
04 Oct 2026, 12:17 AM
Tags
Audience
developers

What happened

Symantec and Carbon Black's Threat Hunter Team report that the actor tracked as Warlock (also Longlegs, Gold Salem, Storm-2603) is still exploiting Microsoft SharePoint Server flaws to attack on-premises deployments, hitting at least four organizations in two months — two critical infrastructure operators (a water utility and a telco), a regional government body, and a university — all in Portuguese- and Spanish-speaking countries. In one intrusion the attackers disabled security software on at least 40 hosts in about two hours, then deployed ransomware to at least 33 hosts by staging the payload in the domain's SYSVOL share so ordinary domain replication delivered it. Entry relies on web shells that harvest the SharePoint farm's ASP.NET machine keys, which are then used to forge a validly signed payload and get remote code execution inside the SharePoint application pool, alongside BYOVD and legitimate tools like Velociraptor for command-and-control.

Why it matters

If your organization runs SharePoint Server on-premises — still common in enterprise and government environments — this is a concrete reason to check patch status and, more importantly, treat ASP.NET machine keys as compromised material: stealing them lets an attacker forge signed payloads and execute code in the SharePoint app pool, so patching alone may not evict them. The SYSVOL staging detail also means your normal AD replication is the delivery mechanism, so watching for unusual file writes to SYSVOL and unexpected security-tool service stops is more useful than another perimeter alert. For everyone else, this is enterprise Windows infrastructure, not something most builders ship with — there is no Malaysia-specific detail in the source, and no stated impact on Malaysian organizations, cloud, payments, or startup tooling.

Discussion angle

Machine-key theft as a persistence problem: if an attacker can forge a signed payload after harvesting SharePoint's ASP.NET machine keys, what does a real remediation actually require — key rotation, farm rebuild, or both — and how many teams have that documented before an incident?

Top