Microsoft says Warlock ransomware deployed in SharePoint attacks as governments scramble
ID: dee303d1-d8b1-58c0-9f4a-31b538a2a80b
STIX ID: report--dee303d1-d8b1-58c0-9f4a-31b538a2a80b
Feed Name: The Record from Recorded Future News
Threat Score
Microsoft and multiple security vendors report active exploitation of SharePoint vulnerability CVE-2025-49706 by a China-based actor (Storm-2603) deploying Warlock ransomware as part of the ToolShell campaign, resulting in hundreds of international government and business compromises and confirmed impacts to several U.S. federal agencies (including NNSA, NIH, DHS); attackers take post-exploitation actions such as disabling Defender and encrypting environments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
