Malik Haidar is a veteran of the cybersecurity trenches, known for his sharp analytical mind and his ability to translate complex threat intelligence into actionable business defense strategies. Having spent years shielding multinational corporations from high-stakes digital incursions, he brings a unique perspective on how modern threat actors like Warlock leverage infrastructure flaws to destabilize critical services. His expertise in integrating the “business side” of security makes him a sought-after voice when discussing how groups like Gold Salem bridge the gap between technical exploits and full-scale organizational paralysis.
This discussion covers the resurgence of the Warlock threat group and their persistent focus on Portuguese- and Spanish-speaking regions across Europe, Africa, and Latin America. We examine the technical mechanics of their SharePoint exploits—specifically the theft of ASP.NET machine keys—as well as their sophisticated use of “Bring Your Own Vulnerable Driver” (BYOVD) tactics to neutralize defenses. Malik also breaks down the rapid lateral movement within critical infrastructure networks, where dozens of hosts can be compromised in a matter of hours through legitimate administrative channels.
On-premises SharePoint servers remain a primary target for actors who steal ASP.NET machine keys. How does this specific focus on SharePoint flaws allow Warlock to bypass traditional defenses so effectively?
The beauty of this attack, from the adversary’s perspective, is that it exploits the inherent trust within a web application’s architecture. When Warlock—whom we also track as Longlegs or Storm-2603—successfully drops a web shell into an on-premises SharePoint environment, they aren’t just looking to steal files; they are hunting for the ASP.NET machine keys. These keys are the “keys to the kingdom” for that specific application pool, allowing the attackers to forge validly signed payloads that the system accepts without question. By achieving remote code execution inside the SharePoint application pool, they bypass the need for traditional credential harvesting in the initial phase. It creates a terrifyingly quiet entry point where the system essentially facilitates its own compromise, as we saw in the recent incidents around July 22, 2026, where they burried deep into networks before security teams even registered a heartbeat of unusual activity.
Warlock has been observed targeting critical infrastructure, including water utilities and telecommunications providers. Based on recent activity, what makes their deployment strategy so devastating for these large-scale environments?
The sheer velocity of their movement is what keeps CISOs awake at night. In one of the most chilling cases we’ve analyzed, these actors managed to push a tool designed to kill security software to at least 40 different hosts in just about two hours. They don’t just hack; they orchestrate, using the domain’s own SYSVOL share to stage their payloads, which then relies on ordinary domain replication to deliver the “poison” to every machine on the network. By the time the incident response team is paged, Warlock has already landed on 33 hosts and established a foothold that is incredibly difficult to root out. For a water utility or a telecom provider, this level of automation means the transition from initial breach to a total ransomware lockout happens faster than the human decision-making cycle can keep up with.
The group utilizes a “Bring Your Own Vulnerable Driver” (BYOVD) technique, specifically exploiting K7RKScan.sys. Why is this method particularly difficult for security teams to detect and mitigate in real-time?
This is a classic “wolf in sheep’s clothing” tactic where the attacker exploits CVE-2025-1055 by loading a legitimate, signed driver that happens to have a known vulnerability. Because the driver is technically “authorized” and signed by a valid vendor, many endpoint detection systems see it as a normal part of a system update or a diagnostic tool. Once that driver is active, Warlock uses it as a surgical instrument to terminate security software from the kernel level, effectively blinding the defenders. It’s a gut-wrenching moment for a security analyst to realize their monitoring tools have been silenced by a driver they thought they could trust. They further mask this by pulling follow-on payloads from legitimate cloud storage sites like catbox.moe or wasabisys.com, which blends their malicious traffic into the everyday noise of a modern digital office.
We have seen an interesting shift toward using legitimate tools like VS Code tunnels and DLL sideloading. How does this “living off the land” approach complicate the forensic process after a ransomware event?
It turns the forensic investigation into a search for a needle in a needle factory. When an actor uses Microsoft Visual Studio Code’s built-in tunnel feature to facilitate remote connections, it looks exactly like a developer working late on a project. There are no “alien” binaries to trigger alarms; it is just a legitimate feature being used for an illegitimate purpose. By the time we start looking at the logs, we see DLL sideloading occurring in memory, which leaves a much smaller footprint on the physical disk than traditional malware. This deliberate use of ToolShell and other related vulnerabilities allows them to maintain persistence for months, as the apparent focus on Portuguese- and Spanish-speaking countries suggests a very patient, perhaps even a deliberately tasked, campaign rather than just random opportunism.
What is your forecast for the evolution of SharePoint-based attacks as we move deeper into the current landscape?
My forecast is that we will see a “long tail” of exploitation where these SharePoint vulnerabilities remain viable for years because the patching cycle for on-premises infrastructure is still too slow. Warlock has proven that even a year after their first major ransomware push, the same entry routes—like the ToolShell flaws—are still wide open in government and education sectors. We should expect these actors to become even more specialized in regional targeting, potentially using localized legitimate software or regional cloud providers to further hide their command-and-control traffic. Unless organizations move toward a more aggressive, automated patching posture for their collaboration servers, SharePoint will continue to be the preferred “front door” for state-linked actors looking to deploy ransomware at scale.

