Warlock ransomware targets SharePoint in water, telecom sector

▼ Summary
– The China-linked ransomware group Warlock targeted critical infrastructure in Portuguese and Spanish-speaking regions by exploiting Microsoft SharePoint zero-day vulnerabilities known as ToolShell.
– Researchers from Symantec and Carbon Black identified the threat actor as Longlegs, noting their use of an AV/EDR killer tool to disable security protections on dozens of hosts.
– The attackers utilized the bring your own vulnerable driver technique with a signed K7RKScan driver to bypass endpoint detection and response systems before deploying ransomware.
– To maintain persistence and lateral movement, the group installed Visual Studio Code Insiders as a service for remote tunneling and used NetExe for Active Directory enumeration.
– The ransomware payload was staged in the SYSVOL share to execute across the network via Group Policy objects, demonstrating a sophisticated multi-stage intrusion method.
Warlock ransomware, a threat actor linked to China, has intensified its campaign against critical infrastructure by exploiting SharePoint vulnerabilities to breach the networks of water utilities, telecommunications providers, regional governments, and universities. Over the last two months, this group has concentrated its efforts on targets in Portuguese and Spanish-speaking regions across Europe, Africa, and Latin America.
The ToolShell Exploit Chain
The group first appeared in June 2025, quickly gaining notoriety for leveraging a chain of zero-day flaws in Microsoft SharePoint collectively known as ToolShell. These vulnerabilities are tracked under identifiers CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771. By August, Microsoft had identified other state-backed entities, specifically Linen Typhoon and Violet Typhoon, as well as the ransomware operator designated as Storm-2603, utilizing these same exploits.
Symantec identifies the primary attacker behind the Warlock ransomware as Longlegs. According to cybersecurity researchers, one specific intrusion initiated on July 22 saw the threat actor deploy a tool that disabled protection software on “at least 40 hosts within about two hours.” Following this disruption, the attackers launched the Warlock ransomware on at least 33 systems.
EDR Elimination and Infrastructure Control
To maintain persistence and evade detection, Longlegs utilizes a sophisticated approach to neutralize endpoint security. In attacks attributed to this group, an AV/EDR-killing tool is deployed via the bring your own vulnerable driver (BYOVD) technique. This method leverages a signed K7RKScan driver susceptible to CVE-2025-1055. Once initial access is secured through on-premises SharePoint vulnerabilities, the attacker drops a web shell compatible with multiple SharePoint versions.
Reconnaissance activities were observed two days after the initial breach, during which the threat actor deleted staging artifacts to cover its tracks. To facilitate remote control, the main executable for Visual Studio Code Insiders was installed as a service, allowing the attackers to connect to compromised machines using VS Code’s built-in tunneling capability. Additionally, the open-source penetration testing framework NetExec was found on one system, aiding in Active Directory enumeration, credential spraying, and remote command execution.
Payload Delivery via SYSVOL
The final stage of the attack unfolded on July 31, immediately following the deployment of the AV/EDR killer. Researchers noted that Warlock ransomware “appeared almost as soon as protection was disabled on each host.” The payload was staged in the domain’s SYSVOL share, a directory that stores public files and replicates across every domain controller.
This distribution method allows for simultaneous execution across an entire network via logon scripts or Group Policy objects, rather than targeting individual hosts sequentially. The report from Symantec and Carbon Black threat hunters emphasizes that ToolShell and related SharePoint flaws remain potent initial access vectors more than a year after the group’s emergence. The analysis includes a comprehensive set of indicators of compromise for files and infrastructure associated with these operations.
(Source: BleepingComputer)




