# Warlock Ransomware Exploits SharePoint in Critical Infrastructure Attacks

> Warlock ransomware targets water and telecom sectors using SharePoint zero-days and BYOVD techniques to disable endpoint protection.

- Published: 2026-10-03T02:57:00.000Z
- Severity: high
- Category: Threat Intel
- Tags: Ransomware, SharePoint, Warlock, CVE-2025-49704, CVE-2025-49706
- CVEs: CVE-2025-49704 (CVSS 0), CVE-2025-49706 (CVSS 0), CVE-2025-53770 (CVSS 0), CVE-2025-53771 (CVSS 0), CVE-2025-1055 (CVSS 0)
- Author: Runtime Rebel Intel
- Primary source: https://www.bleepingcomputer.com/news/security/warlock-ransomware-breach-sharepoint-in-water-telecom-operator-attacks/
- Canonical: https://runtimerebel.com/blog/warlock-ransomware-exploits-sharepoint-in-critical-infrastructure-attacks

## Key points

- Water utilities, telecom providers, and government bodies face active ransomware deployment following initial access via SharePoint vulnerabilities.
- On-premises Microsoft SharePoint deployments are targeted using the ToolShell exploit chain and associated remote access tooling.
- Organizations must immediately patch SharePoint servers, audit SYSVOL shares for unauthorized staging, and monitor for BYOVD activity.

## Overview of Warlock [Ransomware](/glossary#ransomware) Campaigns

The China-linked threat group known as Warlock has launched a series of targeted intrusions against critical infrastructure, including a water utility, a telecommunications provider, a regional government body, and a university. According to [BleepingComputer](https://www.bleepingcomputer.com/news/security/warlock-ransomware-breach-sharepoint-in-water-telecom-operator-attacks/), the campaign predominantly focuses on Portuguese and Spanish-speaking countries across Europe, Africa, and Latin America. Emerging in mid-2025, the [threat actor](/glossary#threat-actor) gained significant notoriety by leveraging a chain of [zero-day](/glossary#zero-day) vulnerabilities in Microsoft SharePoint referred to as ToolShell, which includes [CVE-2025-49704](/cve/cve-2025-49704), [CVE-2025-49706](/cve/cve-2025-49706), [CVE-2025-53770](/cve/cve-2025-53770), and [CVE-2025-53771](https://nvd.nist.gov/vuln/detail/CVE-2025-53771).

Security researchers tracking the activity—identified by Symantec as Longlegs—observe overlap with state-backed actors such as Linen Typhoon and Violet Typhoon, alongside another ransomware cluster designated as Storm-2603. These attacks highlight the ongoing [vulnerability](/glossary#vulnerability) of on-premises collaboration infrastructure to sophisticated intrusion techniques.

## Technical Analysis and TTPs

Intrusions typically commence with the exploitation of on-premises Microsoft SharePoint servers. Once [initial access](/glossary#initial-access) is secured, the adversary deploys a persistent web shell designed for cross-version compatibility. Further analysis of recent campaigns reveals a methodical progression through [reconnaissance](/glossary#reconnaissance), [lateral movement](/glossary#lateral-movement), and [payload](/glossary#payload) staging.

### Evasion and [Defense Evasion](/glossary#defense-evasion) Techniques

A hallmark of the Warlock operation is the systematic disabling of [endpoint](/glossary#endpoint) detection and response ([EDR](/glossary#edr)) and antivirus software prior to ransomware execution. Researchers documented an intrusion where a specialized tool disabled protection software on at least 40 hosts within a two-hour window, immediately preceding the deployment of Warlock ransomware on 33 of those systems. 

To facilitate security software termination, the threat actor utilizes the bring your own vulnerable driver (BYOVD) technique. This involves loading a vulnerable, digitally signed K7RKScan driver associated with [CVE-2025-1055](https://nvd.nist.gov/vuln/detail/CVE-2025-1055) to bypass kernel-level security controls.

### Lateral Movement and Staging

Following reconnaissance and Active Directory enumeration—facilitated by tools such as NetExec—the adversary stages their payloads within the domain's SYSVOL share. Replicating files across every domain controller via SYSVOL allows the attackers to push payloads out for execution simultaneously through Group Policy objects or logon scripts, bypassing the need for individual host-by-host deployment.

Additionally, operators abuse legitimate administrative utilities for continued access. In observed incidents, the main executable for Visual Studio Code Insiders was installed as a service to leverage built-in tunneling capabilities for persistent remote connectivity.

## Actionable Recommendations and Mitigations

Defenders managing on-premises collaboration tools must prioritize [hardening](/glossary#hardening) and visibility to counter these tactics:

* **[Patch](/glossary#patch) Management:** Immediately apply all security updates for Microsoft SharePoint to address the ToolShell vulnerability chain and prevent initial exploitation.
* **Monitor SYSVOL Integrity:** Establish rigorous auditing and file-integrity monitoring on Active Directory SYSVOL shares to detect unauthorized staging of executables or suspicious script modifications.
* **Driver Blocklists:** Enforce Microsoft's recommended driver blocklists to mitigate BYOVD attacks involving vulnerable signed drivers such as the K7RKScan utility.
* **EDR Protection:** Ensure that tamper protection features are actively enforced across all security agents to prevent threat actors from stopping logging and detection services.

**Related:** [Warlock Ransomware Targets Spanish, Portuguese Orgs](/blog/warlock-ransomware-targets-spanish-portuguese-orgs), [Mount Royal University Data Breach: Ransomware Impact & Mitigation](/blog/mount-royal-university-data-breach-ransomware-impact-mitigation)

---

AI-generated analysis from the primary source above; not human-reviewed before publication — verify anything operational against the original (https://runtimerebel.com/editorial). Quote with attribution and a link to the canonical URL: https://runtimerebel.com/blog/warlock-ransomware-exploits-sharepoint-in-critical-infrastructure-attacks
