Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →Warlock ransomware attackers are using vulnerable, internet-facing on-premises SharePoint servers as a route into organizations, then moving beyond the web server to steal credentials, disable security tools and distribute ransomware. In findings published October 1, 2026, Symantec’s Threat Hunter Team reported attacks on at least four organizations in the preceding two months, including a water utility and a telecommunications provider. For SharePoint administrators, patching is urgent—but a patch alone cannot establish whether an intruder already stole machine keys or installed persistence.
What Symantec reported in October 2026
Symantec says the victims were in Portuguese- and Spanish-speaking countries across Europe, Africa and Latin America. They included two critical infrastructure operators—a water utility and a telecommunications provider—as well as a regional government body and a university. The report does not name the organizations, and its four-or-more victim count is not a campaign-wide prevalence estimate.
In one critical-infrastructure intrusion, a tool intended to disable security software reached at least 40 hosts in about two hours. Warlock was then observed on at least 33 hosts in that same intrusion. These are incident-specific figures reported by Symantec, not totals across all of the activity. Symantec’s October 1 report describes the incidents; SecurityWeek’s October 2 article provides secondary coverage.
How the SharePoint foothold can become a domain-wide incident
Symantec describes a chain that starts with exploitation of SharePoint-related vulnerabilities on on-premises servers. The actor placed a webshell in SharePoint’s LAYOUTS directory, stole ASP.NET machine keys and used a forged signed payload to execute code in the SharePoint application pool. The report says newer SharePoint flaws may be in the actor’s arsenal, but it does not map a particular 2026 CVE to each victim intrusion or establish that every named vulnerability was used in every network.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →#1 Best Overall
From web server access to remote control
After gaining a SharePoint foothold, the attackers used DLL sideloading and retrieved payloads from legitimate file-sharing and storage services. Symantec also observed abuse of Visual Studio Code’s tunnel feature for remote access, followed by credential theft and domain reconnaissance. These steps can turn an application-server compromise into access to other systems and accounts.
Disabling defenses and staging ransomware
Symantec observed a vulnerable signed driver used to disable security software and ransomware staged in SYSVOL for broad deployment. Microsoft documented related Warlock activity in 2025 involving credential theft, lateral movement and Group Policy changes to distribute the ransomware. That earlier account is useful context for the potential impact, but it is not proof that every step occurred in every 2026 victim network. Microsoft’s July 2025 account also describes webshells with names resembling spinstall0.aspx and exploitation involving the ToolPane POST path.
What is known—and not known—about the actor
Symantec calls the group Longlegs, also tracked as Storm-2603, and describes it as China-nexus. It links Longlegs to earlier activity clusters named CL-CRI-1040, CamoFei and ChamelGang. Microsoft’s 2025 assessment characterized Storm-2603 as China-based with moderate confidence and said it had not identified links to other known Chinese threat actors. These are attributed vendor assessments, not a definitive public finding of state sponsorship.
Symantec says the recent concentration of victims in Portuguese- and Spanish-speaking countries could reflect opportunistic exploitation of exposed vulnerable servers or deliberate tasking; its report does not resolve which explanation is correct. It also does not provide a population-level statistic for how common these attacks are.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
What SharePoint operators should do now
SharePoint patch status and compromise status are separate questions. Microsoft’s July 2025 guidance concerns on-premises SharePoint Server vulnerabilities; it says SharePoint Online in Microsoft 365 was not affected by those vulnerabilities. Operators should follow current vendor advisories for their exact server version rather than applying that historical distinction to newer flaws.
- Bring supported on-premises servers up to date. Apply the latest applicable security updates promptly and confirm that the server is a supported SharePoint Server version. Microsoft said customers should apply its July 2025 updates immediately; that advice does not replace checking current advisories for later vulnerabilities.
- Harden the application and endpoint protections. Microsoft recommends enabling AMSI in Full Mode with Microsoft Defender Antivirus or an equivalent, and using Microsoft Defender for Endpoint or equivalent monitoring. Apply the current vendor guidance for the server’s configuration.
- Treat possible exposure as an incident to investigate. Review SharePoint and IIS for unexpected files or webshells, including suspicious ASPX files in web-accessible locations; inspect relevant logs and investigate suspicious ToolPane POST activity. Check for stolen or altered ASP.NET machine keys, unexpected accounts, scheduled tasks, IIS persistence and signs of credential theft or lateral movement.
- Rotate machine keys and restart IIS when indicated. Microsoft’s response guidance recommends ASP.NET machine-key rotation and an IIS restart in addition to patching. Coordinate the work with incident responders so it does not disrupt evidence collection or leave compromised access in place.
- Look beyond the SharePoint server. Hunt for security-tool tampering, suspicious remote-access tunnels, payload downloads, unusual Group Policy changes and ransomware staged in SYSVOL. CISA’s August 6, 2025 malware analysis covered six files associated with SharePoint vulnerabilities: two DLLs, one cryptographic key stealer and three web shells. It published detection signatures and indicators for files related to CVE-2025-49704, CVE-2025-49706, CVE-2025-53770 and CVE-2025-53771. Those are historical ToolShell-related materials; use them alongside current advisories and detection content, not as a substitute for them. CISA’s notice and analysis explain the scope.
- Contain and recover only after assessing the environment. If compromise is suspected, involve the organization’s incident-response team, contain infected devices, review scheduled tasks and Group Policy, and reset privileged credentials as appropriate. Microsoft Security Intelligence recommends recovery from offline or immutable backups only after the environment has been verified clean. Microsoft’s WarLock entry provides additional containment and recovery guidance.
Patch state is not the same as security state
| Operational state | What it establishes | What still needs attention |
|---|---|---|
| Internet-facing SharePoint Server is vulnerable | An exposed entry point may remain available for exploitation. | Apply current updates, verify the server’s supported status and assess for prior access. |
| Security update is applied | The patched vulnerability should no longer be an open entry point covered by that update. | Determine whether an attacker already stole machine keys, planted persistence, created accounts or moved into the domain. |
| Compromise assessed and persistence removed | Investigation has addressed the SharePoint foothold and the identified paths into the wider environment. | Continue monitoring and validate that containment and recovery controls are effective. |
| Recovery process tested and environment verified clean | Recovery can proceed from a known-clean state using the organization’s tested process. | Maintain current updates, monitoring and incident-response readiness. |
For an active or suspected intrusion, an endpoint security product is one part of the response—not a replacement for patching, domain-wide threat hunting or incident-response coverage. Symantec’s October 2026 report underscores why: the initial SharePoint compromise was followed by activity aimed at broader access and ransomware deployment.
Quick Recap
Rank #4
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

