Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Warlock ransomware attackers exploited four ToolShell vulnerabilities in internet-facing, on-premises Microsoft SharePoint servers. Reporting from October 1–2, 2026 links the wave to at least a water utility, a telecommunications provider, a regional government and a university in Portuguese- and Spanish-speaking countries. SharePoint Online in Microsoft 365 is not affected by this specific ToolShell guidance.

What happened in the Warlock SharePoint attacks?

The campaign began with public-facing SharePoint exploitation and progressed to web-shell execution, credential theft, lateral movement and ransomware deployment. Symantec findings summarized in 2026 reporting identified at least four victim organizations. Their sectors included water, telecommunications, regional government and higher education, with victims reported across Europe, Africa and Latin America.

Symantec associated the operation with the actor Longlegs. Microsoft tracks the ransomware-deploying activity as Storm-2603 and separately reported exploitation by the China-based actors Linen Typhoon and Violet Typhoon. Microsoft’s wording distinguishes those observations: Linen Typhoon and Violet Typhoon were seen exploiting the vulnerabilities, while Storm-2603 was seen exploiting them to deploy ransomware. These tracking labels describe observed activity, not a public legal attribution of every intrusion.

Reported impact in one intrusion

Measure Reported finding Source and qualification
Organizations affected At least four Symantec findings summarized by Security.com in 2026; the total may be higher.
Hosts with protections disabled At least 40 BleepingComputer reported this occurred within about two hours of the intrusion.
Hosts that received Warlock ransomware At least 33 BleepingComputer’s account of that intrusion.
Reconnaissance and data-theft period About 15 days before encryption Microsoft Security Intelligence’s 2026 update to its WarLock.B description.

How did Warlock breach SharePoint?

Microsoft observed a repeatable chain against internet-facing, on-premises SharePoint servers:

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Exploit the exposed server. Attackers used the ToolShell vulnerabilities to gain an initial foothold through a public SharePoint endpoint.
  2. Install a web shell. The spinstall0.aspx file provided a server-side foothold. Commands ran through the SharePoint worker process w3wp.exe.
  3. Discover the environment. The operators surveyed systems and accounts before broadening the intrusion.
  4. Steal credentials. Microsoft observed Mimikatz used to dump credentials.
  5. Move laterally. PsExec, Impacket and Windows Management Instrumentation (WMI) were used to reach additional hosts.
  6. Establish persistence. The activity included scheduled tasks and IIS-based persistence.
  7. Reduce defenses. Microsoft observed the attackers disabling Microsoft Defender protections. BleepingComputer reported at least 40 hosts with protection disabled in one intrusion.
  8. Deploy the payload. Group Policy was used to distribute Warlock ransomware across the environment.

The sequence explains why patching only the initially exposed server is insufficient after exploitation: credentials, administrative tooling and policy controls may already have been abused elsewhere.

What are the ToolShell CVEs?

The exploited set is collectively called ToolShell. Microsoft identified these four CVEs in the campaign:

Vulnerability What the reporting establishes
CVE-2025-49704 Observed as part of the exploited ToolShell set affecting on-premises SharePoint Server.
CVE-2025-49706 Observed as part of the exploited ToolShell set affecting on-premises SharePoint Server.
CVE-2025-53770 Observed as part of the exploited ToolShell set affecting on-premises SharePoint Server.
CVE-2025-53771 Observed as part of the exploited ToolShell set affecting on-premises SharePoint Server.

The available incident reporting does not assign a separate attack step to each CVE; treat all four as one urgent patching scope rather than trying to remediate only a selected number.

Are SharePoint Online sites affected?

No. Microsoft says this ToolShell guidance applies to on-premises SharePoint Server. SharePoint Online in Microsoft 365 is not impacted by these vulnerabilities according to that guidance. Organizations can still have hybrid exposure if they operate an on-premises farm alongside Microsoft 365, so inventory every internet-facing server and connector instead of assuming a cloud tenant removes all on-premises risk.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What should you do if a SharePoint server is exposed?

Use the following order when a vulnerable or potentially compromised farm is reachable from the internet:

  1. Contain suspected compromise. Disconnect affected systems from the network or isolate them with established incident-response controls. Preserve evidence before wiping or rebuilding.
  2. Patch every farm member. Run a supported SharePoint Server version and install Microsoft’s July 2025 security updates across the farm, not just on the web front end.
  3. Rotate ASP.NET machine keys. Treat existing keys as exposed after exploitation and replace them using Microsoft’s ToolShell mitigation guidance.
  4. Restart IIS. Restart the web services after key rotation and patching so old worker processes and loaded components are not retained.
  5. Enable AMSI in Full Mode. Verify that the Antimalware Scan Interface is active in Full Mode for SharePoint workloads.
  6. Hunt for the foothold. Look for spinstall0.aspx, unusual activity from w3wp.exe, unexpected IIS or scheduled-task persistence, Mimikatz, PsExec, Impacket, WMI and Group Policy changes.
  7. Reset credentials. Change domain-administrator, service-account and other credentials that could have been present on the farm. Rotate them from a clean administrative workstation.
  8. Check for lateral compromise. Review authentication, process, PowerShell, WMI, PsExec and Group Policy logs across connected servers, not only SharePoint logs.
  9. Recover carefully. Restore only from offline or otherwise unconnected backups known to predate the intrusion. Validate the restored environment before reconnecting it.

How can organizations reduce repeat risk?

  • Keep SharePoint Server supported and place internet-facing administration behind tightly controlled access rather than exposing it unnecessarily.
  • Deploy Microsoft Defender for Endpoint or an equivalent endpoint-detection and response control on servers that support it.
  • Restrict and log PsExec, PowerShell and Rclone. Investigate unexpected use, especially from web-server accounts.
  • Use Windows Defender Application Control (WDAC), or an equivalent application-control policy, to block known vulnerable drivers as Microsoft recommends for WarLock.B response.
  • Protect Group Policy administration and monitor policy changes that introduce startup scripts, scheduled tasks or software deployment.
  • Maintain offline or otherwise disconnected backups and test restoration; an online backup reachable with compromised administrator credentials is not a dependable ransomware recovery point.
  • Segment SharePoint from domain controllers, backup infrastructure and high-value databases so a web-server compromise cannot automatically reach every tier.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What is known—and what is not—about this wave?

The published evidence establishes exploitation of on-premises SharePoint, the four ToolShell CVEs, the web-shell and lateral-movement techniques, and ransomware deployment against at least the reported victims. Microsoft’s update describes roughly 15 days of reconnaissance and data theft before encryption in the WarLock.B activity. It does not establish that every victim had the same dwell time or that every organization in the wave has been identified.

The actor names should also be read precisely. Microsoft reported Linen Typhoon and Violet Typhoon exploiting the vulnerabilities and Storm-2603 deploying ransomware; Symantec associated the operation with Longlegs. Those are vendor tracking assessments, and they do not by themselves prove that a particular water utility or telecom operator was attacked by one uniquely identified group.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.