Back to Intelligence

Warlock (China-Linked) Exploiting SharePoint Flaws to Disable Security Tools and Deploy Ransomware: Detection and Hardening Guide

SA
Security Arsenal Team
October 4, 2026
11 min read

The suspected China-linked threat actor tracked as Warlock continues to weaponize Microsoft SharePoint vulnerabilities — likely a mix of previously disclosed and newly identified flaws — in an active campaign hitting organizations in Portuguese- and Spanish-speaking countries. According to the Symantec and Carbon Black Threat Hunter Team, the victims span critical infrastructure, government, and education sectors.

This is not an exploratory espionage operation. Warlock's playbook is explicitly destructive: gain initial access through an internet-facing SharePoint server, disable or blind security tooling, and then deploy an encryption-based payload — ransomware. If your organization runs on-premises SharePoint exposed to the internet, you should treat this as an active, imminent-threat scenario and validate your patch posture, machine key hygiene, and EDR tamper protection today.

Who Is at Risk

  • Organizations running on-premises Microsoft SharePoint Server (Subscription Edition, 2019, 2016) reachable from the internet
  • Government, education, and critical infrastructure entities — particularly those in Latin America, Iberia, and Lusophone regions, though TTPs migrate globally fast
  • Any environment where SharePoint servers lack EDR coverage, AMSI integration, or current cumulative updates

SharePoint Online (Microsoft 365) tenants are not directly affected by on-prem server exploitation, but hybrid environments with on-prem SharePoint remain exposed.

Technical Analysis: The Warlock Attack Chain

Based on the reported tradecraft, the intrusion chain follows a pattern defenders should recognize and instrument for:

1. Initial Access — SharePoint Vulnerability Exploitation. Warlock exploits vulnerabilities in internet-facing on-premises SharePoint servers. The campaign reportedly leverages both older, previously patched flaws (indicating victims with lagging patch cycles) and potentially newer vulnerabilities. Exploitation of this class of SharePoint flaw typically allows unauthenticated remote code execution in the context of the SharePoint web application pool account — giving the attacker code execution via the IIS worker process (w3wp.exe).

2. Webshell Deployment. Post-exploitation, attackers characteristically drop ASPX webshells into SharePoint's web directories — most notably the LAYOUTS folder (C:\Program Files\Common Files\microsoft shared\Web Server Extensions\16\TEMPLATE\LAYOUTS\) — to establish persistent, authenticated remote access that survives reboots and blends into legitimate SharePoint traffic.

3. Security Tool Disablement (Defense Evasion — MITRE ATT&CK T1562.001). Before deploying the encryptor, Warlock actively disables or impairs endpoint security controls. Observable behaviors in this class of operation include:

  • Attempting to stop or delete security services via sc.exe, net.exe stop, or taskkill
  • Tampering with Microsoft Defender via registry modification (DisableAntiSpyware, DisableRealtimeMonitoring) or PowerShell Set-MpPreference
  • Uninstalling or killing EDR agents
  • Clearing event logs (wevtutil cl, Clear-EventLog)

4. Impact — Encryption-Based Payload (T1486). The final stage is a ransomware-style encryption event. Expect precursor behaviors such as shadow copy deletion (vssadmin delete shadows, wmic shadowcopy delete, bcdedit recovery tampering) and mass file encryption.

Exploitation Status

This is confirmed active exploitation in the wild against named sectors, per Symantec/Carbon Black threat hunters. Treat any unpatched, internet-facing SharePoint instance as a presumed target. Because the campaign reportedly abuses both old and new flaws, patching alone is insufficient — you must also hunt for pre-existing compromise (webshells planted before patching) and rotate SharePoint ASP.NET machine keys after patching, a step that is frequently missed and leaves stolen-view-state/webshell access intact.

Detection & Response

Sigma Rules

The following rules target the highest-fidelity behaviors in the Warlock chain: SharePoint worker process spawning shells, webshell drops in SharePoint directories, and security tool tampering preceding ransomware deployment.

YAML
---
title: SharePoint Worker Process Spawning Command Shell or Scripting Engine
id: 3f8a1b72-6c4d-4e9a-bf21-7d5c9a2e8f34
status: experimental
description: Detects the SharePoint IIS worker process (w3wp.exe) spawning cmd, PowerShell, or other scripting engines — a hallmark of SharePoint exploit post-exploitation and webshell activity as observed in Warlock intrusions.
references:
  - https://thehackernews.com/2026/10/warlock-exploits-sharepoint-flaws-to.html
  - https://attack.mitre.org/techniques/T1190/
  - https://attack.mitre.org/techniques/T1505/003/
author: Security Arsenal
date: 2026/10/22
tags:
  - attack.initial_access
  - attack.t1190
  - attack.persistence
  - attack.t1505.003
logsource:
  category: process_creation
  product: windows
detection:
  selection_parent:
    ParentImage|endswith: '\w3wp.exe'
  selection_child:
    Image|endswith:
      - '\cmd.exe'
      - '\powershell.exe'
      - '\pwsh.exe'
      - '\cscript.exe'
      - '\wscript.exe'
      - '\mshta.exe'
      - '\rundll32.exe'
      - '\certutil.exe'
      - '\bitsadmin.exe'
  condition: selection_parent and selection_child
falsepositives:
  - Rare custom SharePoint solutions that invoke scripts from workflows — validate against your environment; this should be near-zero in most orgs
level: high
---
title: Webshell File Created in SharePoint LAYOUTS Directory
id: 9c2e5d41-8b3f-4a67-9c15-2e7f4b8d6a91
status: experimental
description: Detects creation of ASPX/ASP script files in SharePoint TEMPLATE\LAYOUTS or related web directories by non-SharePoint processes — consistent with webshell deployment following SharePoint exploitation.
references:
  - https://thehackernews.com/2026/10/warlock-exploits-sharepoint-flaws-to.html
  - https://attack.mitre.org/techniques/T1505/003/
author: Security Arsenal
date: 2026/10/22
tags:
  - attack.persistence
  - attack.t1505.003
logsource:
  category: file_event
  product: windows
detection:
  selection_path:
    TargetFilename|contains:
      - '\Web Server Extensions\16\TEMPLATE\LAYOUTS\'
      - '\Web Server Extensions\15\TEMPLATE\LAYOUTS\'
      - '\inetpub\wwwroot\wss\'
  selection_ext:
    TargetFilename|endswith:
      - '.aspx'
      - '.asp'
      - '.ashx'
      - '.asmx'
      - '.php'
  filter_installers:
    Image|endswith:
      - '\msiexec.exe'
      - '\setup.exe'
      - '\wsstracing.exe'
  condition: selection_path and selection_ext and not filter_installers
falsepositives:
  - SharePoint cumulative update installations and legitimate custom solution deployments — correlate with patch windows
level: high
---
title: Security Tool Tampering Preceding Ransomware Deployment
id: 5b7d3e18-2f6a-4c94-8d31-4a9c7e2b5f68
status: experimental
description: Detects attempts to disable Defender real-time protection, stop security services, delete shadow copies, or clear event logs — behavior Warlock performs before deploying encryption payloads.
references:
  - https://thehackernews.com/2026/10/warlock-exploits-sharepoint-flaws-to.html
  - https://attack.mitre.org/techniques/T1562/001/
  - https://attack.mitre.org/techniques/T1490/
author: Security Arsenal
date: 2026/10/22
tags:
  - attack.defense_evasion
  - attack.t1562.001
  - attack.impact
  - attack.t1490
logsource:
  category: process_creation
  product: windows
detection:
  selection_defender:
    CommandLine|contains:
      - 'Set-MpPreference'
      - 'DisableRealtimeMonitoring'
      - 'DisableAntiSpyware'
      - 'Add-MpPreference -ExclusionPath'
  selection_shadow:
    CommandLine|contains:
      - 'vssadmin delete shadows'
      - 'vssadmin.exe delete'
      - 'shadowcopy delete'
      - 'wmic shadowcopy'
      - 'bcdedit'
  selection_services:
    CommandLine|contains:
      - 'sc stop'
      - 'sc config'
      - 'sc delete'
      - 'net stop'
      - 'taskkill /f /im'
  selection_logs:
    CommandLine|contains:
      - 'wevtutil cl'
      - 'Clear-EventLog'
  condition: 1 of selection_*
falsepositives:
  - Legitimate administrative scripts (backup software may delete shadow copies; admins occasionally stop services) — baseline and tune; investigate any occurrence on a SharePoint server as high priority
level: high

KQL — Microsoft Sentinel / Defender

This hunt query chains the two critical stages on SharePoint servers: exploitation via the IIS worker process, and subsequent defense-evasion or impact behaviors. Run it across your SharePoint fleet and any server that egresses from SharePoint-adjacent network segments.

KQL — Microsoft Sentinel / Defender
// Hunt: SharePoint exploitation + post-exploit tampering chain (Warlock TTPs)
let SharePointServers = (DeviceNetworkEvents
| where LocalPort in (80, 443) and InitiatingProcessFileName =~ "w3wp.exe"
| summarize by DeviceName);
let SuspiciousChildren = DeviceProcessEvents
| where InitiatingProcessFileName =~ "w3wp.exe"
| where FileName in~ ("cmd.exe", "powershell.exe", "pwsh.exe", "cscript.exe", "wscript.exe",
                      "mshta.exe", "rundll32.exe", "certutil.exe", "bitsadmin.exe", "whoami.exe",
                      "net.exe", "nltest.exe", "quser.exe")
| project DeviceName, TimeGenerated, ShellCmd=ProcessCommandLine, ShellProcess=FileName, AccountName;
let Tampering = DeviceProcessEvents
| where ProcessCommandLine has_any (
    "DisableRealtimeMonitoring", "Set-MpPreference", "Add-MpPreference",
    "vssadmin delete", "shadowcopy delete", "bcdedit",
    "wevtutil cl", "Clear-EventLog", "sc stop", "sc delete")
| project DeviceName, TamperTime=TimeGenerated, TamperCmd=ProcessCommandLine, TamperProcess=FileName;
SuspiciousChildren
| join kind=inner Tampering on DeviceName
| where TamperTime between (TimeGenerated .. TimeGenerated + 72h)
| project DeviceName, ExploitTime=TimeGenerated, ShellCmd, TamperTime, TamperCmd, AccountName
| sort by DeviceName, ExploitTime;

A simpler, broader variant for environments without device-to-role mapping — webshell file drops:

KQL — Microsoft Sentinel / Defender
// Hunt: script files written into SharePoint web directories by non-installer processes
DeviceFileEvents
| where FolderPath has_any ("Web Server Extensions\\15\\TEMPLATE\\LAYOUTS",
                            "Web Server Extensions\\16\\TEMPLATE\\LAYOUTS")
| where FileName endswith_any (".aspx", ".asp", ".ashx", ".asmx", ".php")
| where InitiatingProcessFileName !in~ ("msiexec.exe", "setup.exe", "psconfig.exe", "wsstracing.exe")
| project TimeGenerated, DeviceName, FileName, FolderPath, InitiatingProcessFileName,
          InitiatingProcessCommandLine, SHA256
| sort by TimeGenerated desc;

Velociraptor VQL

Use this artifact to sweep SharePoint servers for recently created or modified script files in the LAYOUTS tree — the most reliable forensic artifact of post-exploitation webshell deployment. Cross-reference timestamps against your patch and maintenance windows; anything outside a legitimate change window is an incident.

VQL — Velociraptor
-- Hunt for webshell artifacts in SharePoint LAYOUTS directories
-- Deploy against all on-prem SharePoint servers; flag files modified outside approved patch windows
LET layouts_roots = glob([
  'C:/Program Files/Common Files/microsoft shared/Web Server Extensions/15/TEMPLATE/LAYOUTS',
  'C:/Program Files/Common Files/microsoft shared/Web Server Extensions/16/TEMPLATE/LAYOUTS'
])

SELECT FullPath,
       Mtime AS Modified,
       Ctime AS Created,
       Size,
       hash(path=FullPath).MD5 AS MD5
FROM glob(globs=layouts_roots + '/**/*.{aspx,asp,ashx,asmx,php}',
          accessor='ntfs')
WHERE Modified > now() - 604800
ORDER BY Modified DESC

Pair the file sweep with a process check for shells parented to the IIS worker process:

VQL — Velociraptor
-- Live hunt: suspicious child processes of w3wp.exe
SELECT Pid, Ppid, Name, Exe, CommandLine, Username, CreateTime
FROM pslist()
WHERE CommandLine =~ 'cmd.exe|powershell|pwsh|cscript|mshta|certutil|bitsadmin|vssadmin|wevtutil'
  AND Ppid IN (SELECT Pid FROM pslist() WHERE Name =~ 'w3wp')

Remediation & Verification Script

Run this PowerShell on every on-prem SharePoint server (elevated). It verifies build/patch level against a minimum baseline you must set, audits for recently dropped script files in LAYOUTS, checks tamper-protection posture, and surfaces suspicious IIS worker children.

PowerShell
# ============================================================
# Warlock / SharePoint Exploitation — Verification & Hardening
# Run elevated on each SharePoint server. Review output; do not
# blindly remediate on production — snapshot first.
# ============================================================

# --- 1. Report SharePoint build (compare against latest CU) ---
$spBuild = (Get-ItemProperty "HKLM:\SOFTWARE\Microsoft\Shared Tools\Web Server Extensions\16.0" -ErrorAction SilentlyContinue).Version
Write-Host "[+] SharePoint build: $spBuild  -- verify against https://learn.microsoft.com/en-us/officeupdates/sharepoint-updates" -ForegroundColor Cyan

# --- 2. Audit LAYOUTS for script files modified in last 14 days ---
$layouts = @(
  "C:\Program Files\Common Files\microsoft shared\Web Server Extensions\15\TEMPLATE\LAYOUTS",
  "C:\Program Files\Common Files\microsoft shared\Web Server Extensions\16\TEMPLATE\LAYOUTS"
)
foreach ($root in $layouts) {
  if (Test-Path $root) {
    Get-ChildItem $root -Recurse -Include *.aspx,*.asp,*.ashx,*.asmx,*.php -ErrorAction SilentlyContinue |
      Where-Object { $_.LastWriteTime -gt (Get-Date).AddDays(-14) } |
      Select-Object FullName, LastWriteTime, Length |
      Format-Table -AutoSize
  }
}

# --- 3. Check Defender tamper protection & real-time status ---
Get-MpComputerStatus | Select-Object AMServiceEnabled, RealTimeProtectionEnabled,
  IsTamperProtected, AntivirusSignatureLastUpdated | Format-List

# --- 4. Look for Defender tampering registry artifacts ---
$defenderPolicy = "HKLM:\SOFTWARE\Policies\Microsoft\Windows Defender"
if (Test-Path $defenderPolicy) {
  Get-ItemProperty $defenderPolicy | Select-Object DisableAntiSpyware, DisableRealtimeMonitoring
}

# --- 5. List suspicious children of w3wp.exe (live state) ---
$w3wp = Get-CimInstance Win32_Process -Filter "Name='w3wp.exe'"
foreach ($p in $w3wp) {
  Get-CimInstance Win32_Process -Filter "ParentProcessId=$($p.ProcessId)" |
    Where-Object { $_.Name -match 'cmd|powershell|pwsh|cscript|wscript|mshta|certutil|vssadmin|wevtutil' } |
    Select-Object ProcessId, Name, CommandLine, CreationDate | Format-List
}

# --- 6. Enable IIS + SharePoint verbose logging if not present ---
# Ensure IIS logs (including POST bodies via failed-request tracing where feasible)
# and SharePoint ULS logs are retained >= 180 days and shipped to your SIEM.
Write-Host "[+] Confirm IIS logs at C:\inetpub\logs\LogFiles are forwarded to SIEM." -ForegroundColor Cyan

Remediation & Hardening

  1. Patch immediately. Apply the latest SharePoint cumulative updates on all on-prem instances (Subscription Edition, 2019, 2016). Verify builds against the Microsoft SharePoint Updates page and cross-check CVE coverage in the relevant Microsoft Security Update Guide entries. Because Warlock exploits both old and new flaws, a missed CU from any prior cycle leaves you exposed.

  2. Rotate the ASP.NET machine keys after patching. SharePoint exploitation chains frequently steal ValidationKey/DecryptionKey material, enabling forged ViewState payloads that survive patching. After applying updates, rotate machine keys on every SharePoint server in the farm and restart IIS. Microsoft documents this step in its SharePoint exploitation mitigation guidance — skipping it is the single most common remediation failure we see in IR engagements.

  3. Take SharePoint off the internet, or put it behind a VPN/WAF. If business function permits, remove direct internet exposure. If not, front SharePoint with a WAF with current virtual-patch rules and enforce restrictive egress rules on the SharePoint servers (they have no business initiating arbitrary outbound connections).

  4. Enable AMSI integration for SharePoint. SharePoint Server integrates with AMSI to scan requests at the HTTP layer; ensure AMSI is enabled (it's on by default in current builds for Subscription Edition) and that your AV provider registers an AMSI provider on the server.

  5. Enable Tamper Protection and EDR in block mode on SharePoint servers. Warlock's security-tool disablement stage only succeeds where tamper protection is off or the server lacks EDR coverage entirely. Deploy Defender for Endpoint (or your EDR of choice) to all SharePoint servers — a gap we routinely find because teams treat them as "application servers, not endpoints."

  6. Hunt for pre-existing compromise before declaring clean. Patching does not remove webshells already planted. Run the VQL artifact and KQL file-drop query above across the farm; review IIS logs for anomalous POST requests to unexpected ASPX paths; check for unauthorized SharePoint service accounts and recently created local admin accounts.

  7. Restrict service account privileges. The SharePoint farm and application pool accounts should not be local administrators beyond documented requirements and must never hold Domain Admin rights. Constraining the blast radius of a compromised w3wp.exe is the difference between a contained event and a domain-wide ransomware incident.

  8. Monitor for encryption precursors. Alert on shadow copy deletion, bcdedit recovery changes, and bulk file rename/write bursts on SharePoint servers and adjacent file shares. Your last line of defense against Warlock's encryptor is detecting the setup behaviors before the payload runs.

Bottom Line

Warlock is running a repeatable, industrialized playbook: SharePoint vulnerability → webshell → security tool kill → ransomware. Every stage is detectable, and every stage is preventable — but only if SharePoint servers are treated as the tier-zero internet-facing assets they are. Patch, rotate machine keys, hunt for webshells dropped before you patched, and put tamper-protected EDR on every SharePoint box. Organizations in government, education, and critical infrastructure — especially in Portuguese- and Spanish-speaking regions — should assume they are in scope for this campaign.

Related Resources

Security Arsenal Healthcare Cybersecurity AlertMonitor Platform Book a SOC Assessment healthcare Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.