Warlock Ransomware Targets Critical Infrastructure via SharePoint Exploits

ISLAMABAD: A China-linked ransomware group known as Warlock is actively exploiting vulnerabilities in Microsoft SharePoint to infiltrate critical infrastructure organizations across multiple continents, according to a report released by Symantec’s Threat Hunter Team on October 3.

Warlock, also referred to as Gold Salem, Longlegs, and Storm-2603 by Microsoft, first emerged on the Russian-language RAMP forum in June 2025. The group has since escalated its operations, targeting various sectors and raising alarms among cybersecurity experts regarding the potential for widespread disruption.

The implications of these attacks are significant, as they threaten not only the integrity of essential services but also the safety of sensitive data. Experts warn that organizations must enhance their cybersecurity measures to defend against such sophisticated threats, which could lead to severe economic and operational consequences.

In response to these developments, cybersecurity agencies are expected to intensify their investigations into Warlock’s activities. Organizations are urged to implement immediate security updates and conduct thorough assessments of their systems to mitigate risks associated with these vulnerabilities.