Overview of Warlock Ransomware Campaigns
The China-linked threat group known as Warlock has launched a series of targeted intrusions against critical infrastructure, including a water utility, a telecommunications provider, a regional government body, and a university. According to BleepingComputer, the campaign predominantly focuses on Portuguese and Spanish-speaking countries across Europe, Africa, and Latin America. Emerging in mid-2025, the threat actor gained significant notoriety by leveraging a chain of zero-day vulnerabilities in Microsoft SharePoint referred to as ToolShell, which includes CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771.
Security researchers tracking the activity—identified by Symantec as Longlegs—observe overlap with state-backed actors such as Linen Typhoon and Violet Typhoon, alongside another ransomware cluster designated as Storm-2603. These attacks highlight the ongoing vulnerability of on-premises collaboration infrastructure to sophisticated intrusion techniques.
Technical Analysis and TTPs
Intrusions typically commence with the exploitation of on-premises Microsoft SharePoint servers. Once initial access is secured, the adversary deploys a persistent web shell designed for cross-version compatibility. Further analysis of recent campaigns reveals a methodical progression through reconnaissance, lateral movement, and payload staging.
Evasion and Defense Evasion Techniques
A hallmark of the Warlock operation is the systematic disabling of endpoint detection and response (EDR) and antivirus software prior to ransomware execution. Researchers documented an intrusion where a specialized tool disabled protection software on at least 40 hosts within a two-hour window, immediately preceding the deployment of Warlock ransomware on 33 of those systems.
To facilitate security software termination, the threat actor utilizes the bring your own vulnerable driver (BYOVD) technique. This involves loading a vulnerable, digitally signed K7RKScan driver associated with CVE-2025-1055 to bypass kernel-level security controls.
Lateral Movement and Staging
Following reconnaissance and Active Directory enumeration—facilitated by tools such as NetExec—the adversary stages their payloads within the domain’s SYSVOL share. Replicating files across every domain controller via SYSVOL allows the attackers to push payloads out for execution simultaneously through Group Policy objects or logon scripts, bypassing the need for individual host-by-host deployment.
Additionally, operators abuse legitimate administrative utilities for continued access. In observed incidents, the main executable for Visual Studio Code Insiders was installed as a service to leverage built-in tunneling capabilities for persistent remote connectivity.
Actionable Recommendations and Mitigations
Defenders managing on-premises collaboration tools must prioritize hardening and visibility to counter these tactics:
- Patch Management: Immediately apply all security updates for Microsoft SharePoint to address the ToolShell vulnerability chain and prevent initial exploitation.
- Monitor SYSVOL Integrity: Establish rigorous auditing and file-integrity monitoring on Active Directory SYSVOL shares to detect unauthorized staging of executables or suspicious script modifications.
- Driver Blocklists: Enforce Microsoft’s recommended driver blocklists to mitigate BYOVD attacks involving vulnerable signed drivers such as the K7RKScan utility.
- EDR Protection: Ensure that tamper protection features are actively enforced across all security agents to prevent threat actors from stopping logging and detection services.
Related: Warlock Ransomware Targets Spanish, Portuguese Orgs, Mount Royal University Data Breach: Ransomware Impact & Mitigation