Warlock, also known as Gold Salem, Longlegs, and Storm-2603, is still exploiting Microsoft SharePoint vulnerabilities to attack organizations in Portuguese- and Spanish-speaking countries across Europe, Africa, and Latin America. The group has targeted critical infrastructure, government, and education sectors while using web shells, BYOVD, legitimate tools, and SYSVOL staging to disable defenses and deploy ransomware. #Warlock #GoldSalem #Longlegs #Storm2603 #ToolShell #SmarterTools #SmarterMail #K7RKScan.sys #SharePoint
Keypoints
- Warlock continues to exploit Microsoft SharePoint vulnerabilities in ongoing attacks.
- The group has targeted critical infrastructure, government, and university organizations.
- Victims were mainly in Portuguese- and Spanish-speaking countries.
- Attackers used web shells, DLL sideloading, and BYOVD to disable security tools.
- Warlock staged payloads in SYSVOL and used VS Code tunnels for deeper access.
Read More: https://thehackernews.com/2026/10/warlock-exploits-sharepoint-flaws-to.html