Skip to main content
Emerging ThreatsMalware & Ransomware

Warlock Ransomware Exploits SharePoint in Global Attacks

Server room with rows of computer equipment and network gear in a neutral, institutional space.
“at least 40 hosts within about two hours,” Symantec researchers said, describing a single Warlock intrusion that disabled endpoint protection across an environment before a fast, widespread ransomware detonation.

ToolShell zero-days and the origin of access

The ransomware group Warlock — described in the report as China-linked and identified by Symantec as Longlegs — first emerged in June 2025 and earned wider notice a month later after exploiting a chain of Microsoft SharePoint zero-days tracked as ToolShell (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, CVE-2025-53771). Symantec and Carbon Black researchers say Warlock’s initial access pattern typically begins with exploiting vulnerabilities in on-premises SharePoint deployments and dropping a web shell designed to function across multiple SharePoint versions.

July 22 intrusion: AV/EDR killing, reconnaissance, and July 31 detonation

In the intrusion that began on July 22, the threat actor used tools to disable protection software on “at least 40 hosts within about two hours,” then launched Warlock ransomware on at least 33 hosts, the researchers report. Two days after initial access the actor carried out reconnaissance and deleted apparent staging artifacts. The final stage of the intrusion occurred on July 31, when Warlock ransomware “appearing almost as soon as protection was disabled on each host.”

Techniques observed: BYOVD, SYSVOL staging, and VS Code tunneling

The researchers provide several specific technical details about how the campaign spread and persisted. In some incidents attributed to Longlegs, the attackers deployed an AV/EDR-killing capability using the bring-your-own vulnerable driver (BYOVD) technique. That deployment relied on a signed K7RKScan driver that was vulnerable to CVE-2025-1055, according to Symantec and Carbon Black.

Ransomware payloads in the observed intrusions were staged in the domain’s SYSVOL share — a replicated location on domain controllers that stores files intended for logon scripts and Group Policy objects. The report notes that staging a payload in SYSVOL is “a known method of pushing a payload out for execution by a logon script or Group Policy object across an entire network at once, rather than one host at a time.”

To sustain remote access, the attackers installed the main executable file for Visual Studio Code Insiders as a service on compromised systems and used VS Code’s built-in tunneling capability to connect remotely. On at least one system the researchers found NetExec, an open-source penetration testing framework used to help enumerate Active Directory, conduct credential spraying, and execute commands remotely.

Geographic focus and targets

Over the past two months the threat actor concentrated on Portuguese- and Spanish-speaking countries across Europe, Africa, and Latin America, according to the report. Targets identified in the advisory include a water utility, a telecom provider, a regional government body, and a university. Symantec attributes the development of the Warlock ransomware to the actor it calls Longlegs; Microsoft has observed other groups — including state-backed actors Linen Typhoon and Violet Typhoon, plus a ransomware actor tracked as Storm-2603 — using ToolShell exploits by August.

What this means for security teams, policymakers, and affected organizations

  • Security teams and technologists: The report highlights that on-premises SharePoint deployments remain a viable initial access vector and that attackers can combine web shells, BYOVD drivers, SYSVOL staging, and tunneling tools to disable protections and rapidly deploy ransomware across domain-joined hosts.
  • Policymakers and regulators: Microsoft’s and vendor research showing multiple actors — including state-backed groups and ransomware gangs — using the same SharePoint toolchain underscores the cross-cutting risk posed by unpatched enterprise collaboration servers and signed drivers with known vulnerabilities.
  • Affected enterprises and procurement leaders: The researchers provided a set of indicators of compromise for files and infrastructure used in these attacks; organizations that manage on-premises SharePoint, domain controllers, and endpoint driver inventories are the most directly implicated by the tactics described.

Symantec and Carbon Black’s report concludes with a warning: ToolShell and other SharePoint vulnerabilities remain viable initial access vectors, more than a year after Warlock first emerged exploiting SharePoint flaws. The detailed chain observed in July — rapid AV/EDR disabling across dozens of hosts, SYSVOL staging, and immediate ransomware execution once protections were neutralized — offers a clear technical playbook that defenders will need to see and mitigate if similar campaigns recur.

Read the original Symantec/Carbon Black summary at https://www.bleepingcomputer.com/news/security/warlock-ransomware-breach-sharepoint-in-water-telecom-operator-attacks/