logo

Microsoft says Warlock ransomware deployed in SharePoint attacks as governments scramble

ID: dee303d1-d8b1-58c0-9f4a-31b538a2a80b

STIX ID: report--dee303d1-d8b1-58c0-9f4a-31b538a2a80b

Feed Name: The Record from Recorded Future News

Threat Score
90/100

Date Published: 2025-07-24

Date Updated: 2026-05-01

...
...

Microsoft and multiple security vendors report active exploitation of SharePoint vulnerability CVE-2025-49706 by a China-based actor (Storm-2603) deploying Warlock ransomware as part of the ToolShell campaign, resulting in hundreds of international government and business compromises and confirmed impacts to several U.S. federal agencies (including NNSA, NIH, DHS); attackers take post-exploitation actions such as disabling Defender and encrypting environments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.