Skip to main content
HIGH Threat Intel #Ransomware#SharePoint

Warlock Ransomware Exploits SharePoint in Critical Infrastructure Attacks

3 min read Runtime Rebel Intel
Primary source: bleepingcomputer.com

This article was written by a language model from the source above and was not reviewed by a human before publication. Verify anything operational against the original. Editorial policy

Key points
  • Water utilities, telecom providers, and government bodies face active ransomware deployment following initial access via SharePoint vulnerabilities.
  • On-premises Microsoft SharePoint deployments are targeted using the ToolShell exploit chain and associated remote access tooling.
  • Organizations must immediately patch SharePoint servers, audit SYSVOL shares for unauthorized staging, and monitor for BYOVD activity.

Advertisement

Overview of Warlock Ransomware Campaigns

The China-linked threat group known as Warlock has launched a series of targeted intrusions against critical infrastructure, including a water utility, a telecommunications provider, a regional government body, and a university. According to BleepingComputer, the campaign predominantly focuses on Portuguese and Spanish-speaking countries across Europe, Africa, and Latin America. Emerging in mid-2025, the threat actor gained significant notoriety by leveraging a chain of zero-day vulnerabilities in Microsoft SharePoint referred to as ToolShell, which includes CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771.

Security researchers tracking the activity—identified by Symantec as Longlegs—observe overlap with state-backed actors such as Linen Typhoon and Violet Typhoon, alongside another ransomware cluster designated as Storm-2603. These attacks highlight the ongoing vulnerability of on-premises collaboration infrastructure to sophisticated intrusion techniques.

Technical Analysis and TTPs

Intrusions typically commence with the exploitation of on-premises Microsoft SharePoint servers. Once initial access is secured, the adversary deploys a persistent web shell designed for cross-version compatibility. Further analysis of recent campaigns reveals a methodical progression through reconnaissance, lateral movement, and payload staging.

Evasion and Defense Evasion Techniques

A hallmark of the Warlock operation is the systematic disabling of endpoint detection and response (EDR) and antivirus software prior to ransomware execution. Researchers documented an intrusion where a specialized tool disabled protection software on at least 40 hosts within a two-hour window, immediately preceding the deployment of Warlock ransomware on 33 of those systems.

To facilitate security software termination, the threat actor utilizes the bring your own vulnerable driver (BYOVD) technique. This involves loading a vulnerable, digitally signed K7RKScan driver associated with CVE-2025-1055 to bypass kernel-level security controls.

Lateral Movement and Staging

Following reconnaissance and Active Directory enumeration—facilitated by tools such as NetExec—the adversary stages their payloads within the domain’s SYSVOL share. Replicating files across every domain controller via SYSVOL allows the attackers to push payloads out for execution simultaneously through Group Policy objects or logon scripts, bypassing the need for individual host-by-host deployment.

Additionally, operators abuse legitimate administrative utilities for continued access. In observed incidents, the main executable for Visual Studio Code Insiders was installed as a service to leverage built-in tunneling capabilities for persistent remote connectivity.

Actionable Recommendations and Mitigations

Defenders managing on-premises collaboration tools must prioritize hardening and visibility to counter these tactics:

  • Patch Management: Immediately apply all security updates for Microsoft SharePoint to address the ToolShell vulnerability chain and prevent initial exploitation.
  • Monitor SYSVOL Integrity: Establish rigorous auditing and file-integrity monitoring on Active Directory SYSVOL shares to detect unauthorized staging of executables or suspicious script modifications.
  • Driver Blocklists: Enforce Microsoft’s recommended driver blocklists to mitigate BYOVD attacks involving vulnerable signed drivers such as the K7RKScan utility.
  • EDR Protection: Ensure that tamper protection features are actively enforced across all security agents to prevent threat actors from stopping logging and detection services.

Related: Warlock Ransomware Targets Spanish, Portuguese Orgs, Mount Royal University Data Breach: Ransomware Impact & Mitigation

Advertisement

Advertisement