(An Autonomous Body Recognized by Ministry of Commerce & Industry, Government of India)
Competency based placement focussed Education | Training | Research | Consultancy
C-6, Qutab Institutional Area, Near Old JNU Campus, New Delhi-110016
Regular | Part-time (Online Live Classes) Modes
The Warlock ransomware group has continued exploiting vulnerabilities in Microsoft SharePoint servers to break into organisations, with recent attacks affecting critical infrastructure, government and education-related targets. According to cybersecurity researchers, the group has targeted a water utility, a telecommunications provider, a regional government organisation and a university in Portuguese- and Spanish-speaking countries.
Researchers track the threat actor behind the activity as Longlegs, also known as Storm-2603. The group has repeatedly used weaknesses in on-premises Microsoft SharePoint installations as an entry point for its operations. Warlock ransomware first gained attention in 2025 after attackers were found exploiting SharePoint vulnerabilities associated with the ToolShell attack chain.
Recent investigations show that the group continues to rely on SharePoint flaws while also using additional techniques after gaining access to a victim's network. In one reported incident involving critical infrastructure, attackers deployed a tool designed to disable security software on at least 40 systems within roughly two hours. Warlock ransomware was subsequently deployed on at least 33 machines.
The attackers have also been observed using legitimate system tools and services to maintain access, conduct reconnaissance and execute malicious commands. Security researchers say the activity demonstrates how vulnerabilities in widely used enterprise software can provide attackers with a route into larger networks.
The continued attacks have raised concerns for organisations operating essential services, particularly because SharePoint is widely used for collaboration and document management. Researchers have stressed the need for organisations to keep exposed SharePoint systems patched and closely monitor unusual activity.
The latest findings show that ransomware operations are continuing to combine software vulnerabilities with techniques designed to bypass or disable security controls, increasing the potential impact of a successful network intrusion.
02-10-2026