Warlock is Windows-targeting ransomware that emerged in June 2025. It encrypts files and leaves ransom demands, and can terminate backup, database, security, and productivity services and processes to hinder recovery and maximize disruption. Its operators are associated with the China-nexus threat actor tracked as Longlegs by Symantec and Storm-2603 by Microsoft. Chinese state sponsorship has not been established.
Warlock deployments have prominently followed exploitation of internet-facing, on-premises Microsoft SharePoint Server. Associated attacks exploited the ToolShell vulnerabilities CVE-2025-49704 and CVE-2025-49706 and their related patch-bypass vulnerabilities CVE-2025-53770 and CVE-2025-53771. The operators install webshells and steal ASP.NET machine keys to forge signed payloads and execute code within SharePoint application pools. Subsequent intrusion activity includes credential dumping, Active Directory reconnaissance, lateral movement, DLL sideloading, and abuse of legitimate remote-access tools, including Visual Studio Code tunnels and Velociraptor. Separate vulnerable-driver utilities are used to disable endpoint protection before ransomware deployment. Data exfiltration using Rclone has also been observed in Warlock attacks.
The operators distribute Warlock through compromised Active Directory infrastructure, including Group Policy and domain replication shares. In a July 2026 critical-infrastructure intrusion, they disabled security software on at least 40 hosts within approximately two hours and subsequently deployed Warlock to at least 33 systems using normal Distributed File System Replication. Victims span critical infrastructure, government, education, engineering, and other enterprise sectors. Recent campaigns have affected water utilities, telecommunications providers, regional government bodies, and universities in Portuguese- and Spanish-speaking countries across Europe, Africa, and Latin America.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
In July 2025, Microsoft disclosed active exploitation of on-premises SharePoint servers, targeting two critical vulnerabilities: CVE-2025-49706 (an improper authentication/spoofing flaw) and CVE-2025-49704 (a code injection/remote code execution, or RCE, vulnerability).
CVE-2025-49704 (a code injection/remote code execution, or RCE, vulnerability). When chained together, these vulnerabilities allowed authorized attackers to gain remote code execution and access or alter sensitive information.
The original ToolShell exploit chain involved CVE-2025-49704 and CVE-2025-49706, with subsequent exploitation activity involving the related CVE-2025-53770 and CVE-2025-53771 vulnerabilities. | A China-nexus threat actor tracked by Symantec as Longlegs is continuing to exploit vulnerabilities in on-premises Microsoft SharePoint Server to deploy Warlock ransomware, with recent victims including water and telecommunications operators, a regional government body, and a university.
The original ToolShell exploit chain involved CVE-2025-49704 and CVE-2025-49706, with subsequent exploitation activity involving the related CVE-2025-53770 and CVE-2025-53771 vulnerabilities. | A China-nexus threat actor tracked by Symantec as Longlegs is continuing to exploit vulnerabilities in on-premises Microsoft SharePoint Server to deploy Warlock ransomware, with recent victims including water and telecommunications operators, a regional government body, and a university.
Symantec has observed the group abusing the signed but vulnerable K7RKScan driver, associated with CVE-2025-1055, to terminate protected security processes at the kernel level before ransomware deployment.
A high-severity bug in Microsoft SharePoint that’s been exploited since early July has been abused by ransomware, according to an Aug. 10 update to the Cybersecurity and Infrastructure Security Agency's Known Exploited Vulnerabilities (KEV) catalog. CISA offered no more information on the nature of the ransomware attack, but the CVSS 8.8 flaw — CVE-2026-45659 — was added to the agency’s KEV on July 1 and patched by Microsoft in late May. | “They exploited the ToolShell zero-day chain in July 2025 to deploy Warlock ransomware, and now they're back doing the same thing with CVE-2026-45659,” said Calderone.
13 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
A China-nexus threat actor tracked by Symantec as Longlegs is continuing to exploit vulnerabilities in on-premises Microsoft SharePoint Server to deploy Warlock ransomware, with recent victims including water and telecommunications operators, a regional government body, and a university.
A China-nexus threat actor tracked by Symantec as Longlegs is continuing to exploit vulnerabilities in on-premises Microsoft SharePoint Server to deploy Warlock ransomware, with recent victims including water and telecommunications operators, a regional government body, and a university.
Symantec published research on active exploitation of several SharePoint vulnerabilities by a China-nexus cluster called Warlock. That group has been deploying its namesake ransomware against organizations in Portuguese- and Spanish-speaking regions.
A China-nexus threat actor is continuing to exploit Microsoft SharePoint Server vulnerabilities to deploy Warlock ransomware, with recent attacks striking essential-service and public-sector organizations across Portuguese- and Spanish-speaking countries.
A China-nexus threat actor is continuing to exploit Microsoft SharePoint Server vulnerabilities to deploy Warlock ransomware, with recent attacks striking essential-service and public-sector organizations across Portuguese- and Spanish-speaking countries.
The ransomware encrypted files, appending the extension .x2anylock to each encrypted file (hence Warlock’s alternative naming scheme “X2anylock”).
14 distinct techniques documented for this family, organized by ATT&CK tactic.
"That vulnerability, an authentication bypass that can be used to reset admin passwords..."
54 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
104 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Warlock is a ransomware family that emerged in June 2025. Symantec assesses that Longlegs develops and deploys it. Its deployment follows SharePoint exploitation, webshell installation, reconnaissance, lateral movement, and endpoint-security disruption. In a documented July 2026 critical infrastructure intrusion, attackers deployed an AV/EDR-killing utility to at least 40 additional hosts within approximately two hours and delivered Warlock to at least 33 systems. Ransomware binaries staged in the victim's SYSVOL share were propagated through normal Active Directory replication. The content identifies a China-nexus actor but does not establish Chinese state sponsorship.
Ransomware used against higher-value organizations across Europe, Africa, and Latin America. The reported campaign exploits on-premises Microsoft SharePoint vulnerabilities for initial access, then uses DLL sideloading, a vulnerable signed driver to disable security tools, and living-off-the-land techniques. Staging its payload in a domain controller's SYSVOL share allows normal Active Directory replication to distribute the ransomware to every domain controller, potentially enabling domain-wide encryption while avoiding common remote-execution detection patterns.
Named ransomware associated with one incident involving malicious deployment of Velociraptor. The reference provides no further technical details about the ransomware.
Ransomware described as deployed by the namesake Warlock threat actor following exploitation of SharePoint vulnerabilities. The campaign targets organizations in Latin America and the Iberian Peninsula. It is background context for the Exchange vulnerability discussed in this article; no connection to exploitation of CVE-2026-96940 is established.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.