Fresh research from Broadcom’s Symantec and Carbon Black units links a China-linked extortion crew to a run of SharePoint-driven intrusions. The group, tracked as Warlock, spent about two months targeting at least four victims – a water utility, a telecommunications provider, a regional government body and a university – across Portuguese- and Spanish-speaking countries.
Also cataloged as Gold Salem, Longlegs and Storm-2603, the operators plant web shells that scoop up a SharePoint farm’s ASP.NET machine keys. Those keys let the crew sign a payload the server will trust and run code inside the SharePoint application pool. One victim saw a defense-disabling tool land on roughly 40 machines in about two hours; the ransomware then reached at least 33 hosts through the domain’s SYSVOL share, which ordinary replication spreads automatically.
Besides the 2025 ToolShell flaws, the group has worked newer SharePoint issues, including CVE-2026-32201, CVE-2026-50522 and CVE-2026-55040.
On-premises SharePoint remains common as a hospital intranet and document store, and the same flaw classes drove major healthcare compromises in 2025. Health systems should confirm their SharePoint is patched and never internet-exposed, and hunt for web shells and stolen machine keys before a listing follows.