logo

How Warlock Ransomware Targets Vulnerable SharePoint Servers

ID: dc26fb79-34eb-5fe4-83d0-798a26786d81

STIX ID: report--dc26fb79-34eb-5fe4-83d0-798a26786d81

Feed Name: Dark Reading

Threat Score
78/100

Date Published: 2025-08-20

Date Updated: 2026-04-21

Author: Alexander Culafi

...
...

Trend Micro research details how the Warlock ransomware gang (a LockBit-derived variant linked to Storm-2603) exploited multiple on-premises Microsoft SharePoint vulnerabilities (CVE-2025-49706, CVE-2025-49704, CVE-2025-53770, CVE-2025-53771) to gain code execution, escalate privileges via GPO changes, perform credential dumping (Mimikatz), move laterally over SMB, use DLL sideloading and Cloudflare tunnels for C2, and deploy ransomware; the report emphasizes active exploitation, scale of impact on government and private organizations, and urges immediate patching and layered defenses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.