← Blog · · df00tech

Warlock Ransomware Exploits SharePoint to Hit Water, Telecom, and Government Targets

security-news breach

What happened

According to BleepingComputer, the China-linked ransomware group Warlock has been exploiting SharePoint vulnerabilities to gain initial access into victim networks. Reported victims span a water utility, a telecom provider, a regional government body, and a university — a cross-sector spread typical of opportunistic exploitation of an on-premises, internet-facing application rather than a narrowly targeted campaign.

Why it matters for defenders

On-premises SharePoint servers are high-value targets: they're often internet-exposed, hold broad SSO/authentication trust within an organization, and historically have had several exploitable vulnerability classes (deserialization, auth bypass, SSRF). Attackers are using them as a beachhead rather than the end goal, which means any organization running exposed SharePoint — regardless of sector — should treat this as a reminder that it's an attractive, high-trust entry point for ransomware operators. The victim mix here (critical infrastructure, government, education) underscores that Warlock is not being selective about target sector, only about exploitable exposure.

What defenders should watch for now

  • Inventory and patch status of all internet-facing and internal SharePoint (on-prem) servers — confirm current patch levels against the latest Microsoft advisories.
  • Hunt for anomalous IIS/w3wp.exe child process activity, unexpected .aspx file writes to SharePoint web directories, and unusual outbound connections from SharePoint hosts.
  • Review SharePoint and IIS logs for suspicious POST requests to known vulnerable endpoints and for signs of webshell deployment.
  • Monitor for post-exploitation indicators consistent with ransomware staging: credential dumping, lateral movement via SMB/RDP, and use of legitimate admin tools (living-off-the-land) following SharePoint compromise.
  • Ensure SharePoint servers are isolated from critical OT/ICS networks where applicable, particularly for water utility environments.

Developing story

This is a net-new report and specific technical details — the exact vulnerabilities exploited, timeline, and full victim list — have not yet been independently confirmed or exhaustively documented. We'll update our coverage as more detail emerges. Read the original reporting at BleepingComputer.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.