Warning for Organizations: Microsoft Alerts About Ransomware Attacks on On-Premises SharePoint Servers

Listen to this Post

Featured Image
In a significant update for businesses relying on on-premises SharePoint servers, Microsoft has issued a critical warning about ongoing ransomware campaigns targeting these systems. The tech giant has confirmed that hackers are exploiting vulnerabilities in these servers to deploy ransomware, specifically identifying a threat actor known as Storm-2603. This alarming development highlights a new wave of cyberattacks that are financially motivated, with hackers using Warlock ransomware to paralyze networks and demand cryptocurrency payments.

the Issue

Microsoft’s Threat Intelligence team has confirmed that a group called Storm-2603 is behind a series of attacks exploiting vulnerabilities in on-premises SharePoint servers. Previously, these vulnerabilities were primarily associated with data exfiltration, but recent activity has shifted towards more aggressive financial attacks. The Warlock ransomware is being used to hold systems hostage, demanding cryptocurrency payments for their release. The attack begins when hackers exploit an internet-facing SharePoint server, gaining access via a malicious payload called spinstall0.aspx. This breach allows them to deploy ransomware, crippling networks and causing extensive disruption.

Importantly, the issue does not affect SharePoint Online, but on-premises versions, including SharePoint 2016, 2019, and Subscription Edition, remain vulnerable if not patched. The attacks, linked to three China-based hacking groups—Linen Typhoon, Violet Typhoon, and Storm-2603—have impacted organizations in various sectors, including government agencies, energy companies, and universities, across the United States, Europe, and the Middle East.

What Undercode Says:

The ongoing attacks targeting on-premises SharePoint servers underscore the need for robust cybersecurity practices, particularly when managing legacy infrastructure. Microsoft’s identification of Storm-2603 as the threat actor indicates a highly organized and sophisticated group behind the ransomware campaigns. The switch from data exfiltration to financial motivations is a troubling trend, suggesting that cybercriminals are increasingly seeking profit over information theft.

The Warlock ransomware, in particular, is designed to lock systems, forcing victims to pay ransom in cryptocurrency, a method which has proven effective for hackers in the past. However, this attack also highlights a larger concern about outdated systems. The use of on-premises servers, which are often left unpatched or unsupported, provides an attractive target for threat actors.

While SharePoint Online remains unaffected, this does little to comfort organizations still operating on-premises versions. Many businesses are reluctant to move entirely to the cloud, but this attack serves as a stark reminder that outdated on-premises infrastructure can expose sensitive data and disrupt critical services.

For organizations still using on-premises SharePoint servers, it’s crucial to follow Microsoft’s recommended guidelines: enabling Antimalware Scan Interface (AMSI) integration, deploying Defender AV, and using Defender for Endpoint to monitor for suspicious activity. In cases where AMSI cannot be enabled, disconnecting servers from the internet is a critical step to mitigate risk.

Fact Checker Results

✅ Microsoft’s identification of the hacker group Storm-2603 is accurate, and the vulnerability exploitation is confirmed.
✅ The Warlock ransomware has been specifically linked to these attacks.
✅ The breach affects various sectors, but no classified data from the National Nuclear Security Administration was compromised.

Prediction:

As cybersecurity threats continue to evolve, we can expect to see more sophisticated ransomware campaigns targeting legacy systems. The rise in financial motivations, particularly through cryptocurrency demands, will likely push organizations to adopt more comprehensive cybersecurity measures. Future trends may include an increased shift towards cloud services as businesses seek to avoid the risks posed by on-premises infrastructure. Additionally, more robust patches and real-time threat detection systems will become a standard to mitigate such vulnerabilities.

References:

Reported By: timesofindia.indiatimes.com
Extra Source Hub:
https://www.linkedin.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin