New research published on 3 October shows the Warlock ransomware group is still breaking into Microsoft SharePoint servers, more than a year after the group first appeared. The most recent intrusion in the report dates from 22 July, which tells you something important: the flaws involved have had fixes available for a long time, and attackers are still finding servers that never received them.

The victims named in this campaign are mainly in Spanish and Portuguese speaking countries, including a water utility, a telecoms provider and schools. But the method is generic, and it works on any organisation running an unpatched, self-hosted SharePoint server, including UK businesses.

How the attack works

The attackers start by exploiting known SharePoint flaws, often called ToolShell, to plant a small web shell on the server. From there they steal the server’s internal cryptographic keys. With those keys they can forge requests that SharePoint trusts, which lets them run commands on the machine as if they were legitimate.

The next step is what makes this campaign notable. They load a vulnerable driver to switch off the security software running on the server, then stage the ransomware in a shared folder that is distributed across the whole network. Finally they set up a remote access tunnel using a legitimate developer tool, so they can get back in even if you find the first foothold.

Switching off antivirus is the point where many small firms assume they are protected when they are not. If your only defence is software running on the same server, an attacker with enough access can simply turn it off.

What UK SMEs should check

Do you run SharePoint Server yourself? Many small businesses use SharePoint Online through Microsoft 365, which Microsoft patches for you and is not affected in this way. The risk is for self-hosted, on-premises servers, often run by an IT provider in an office or a data centre.

Is it fully patched? Ask for written confirmation that the latest SharePoint security updates are installed. We have covered earlier SharePoint warnings, including the July on-premise patch alert, and anything missed then is still exposed now.

Have the keys been rotated? Patching does not remove attackers who already stole the machine keys. After patching, your IT provider should rotate them and restart the service.

Is it exposed to the internet? If staff do not need to reach SharePoint from outside, restrict access so it sits behind a VPN or similar control.

Do you have backups you cannot touch from the network? Ransomware stages itself widely before it triggers, so keep at least one backup copy offline or immutable, and test a restore.

Worth considering

If you only use SharePoint for shared files and a small intranet, moving to the cloud version removes the patching burden entirely. And if you hold years of old documents on a server purely because nobody has dared delete them, an organised archive such as Archive.Partners can take them off the live network, which shrinks what an attacker could encrypt or steal.

The takeaway

Old, fixed flaws still cause new breaches. This week, find out whether you run SharePoint on your own server, get written proof it is patched, ask for the keys to be rotated and confirm you hold a backup the network cannot reach.