logo

Microsoft: SharePoint flaws exploited in Warlock ransomware attacks

ID: 93cb8615-859c-53d2-984c-5365158bd133

STIX ID: report--93cb8615-859c-53d2-984c-5365158bd133

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2025-07-24

Date Updated: 2026-07-18

Author: Sergiu Gatlan

...
...

**Executive summary:** A China-based threat actor tracked as Storm-2603 is actively exploiting multiple SharePoint zero-day vulnerabilities (ToolShell chain including CVE-2025-49706, CVE-2025-49704, CVE-2025-53770) to deploy Warlock (and previously LockBit) ransomware; attackers use Mimikatz, PsExec, Impacket, WMI and GPO modifications to move laterally and encrypt systems, with reports of hundreds of compromised SharePoint servers and breaches affecting multiple U.S. and international government entities, while Microsoft and CISA have issued patches and mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.