Warlock Ransomware Uses SharePoint Flaws to Breach Networks


sharepoint ransomware
Image credit: Microsoft

Warlock ransomware is targeting critical organizations, including water, telecom, government, and education entities, with attackers using SharePoint vulnerabilities to gain initial access.

Warlock targets critical organizations

The China-linked ransomware group Warlock has targeted a water utility, telecom provider, regional government body, and university.

Recent attacks have focused largely on Portuguese- and Spanish-speaking organizations across Europe, Africa, and Latin America.

Warlock, which Symantec also tracks as Longlegs, first gained attention after exploiting the ToolShell SharePoint vulnerability chain to breach enterprise networks.

SharePoint flaws give attackers initial access

Warlock typically exploits vulnerabilities in on-premises SharePoint servers before deploying a web shell that works across multiple SharePoint versions.

In one July attack, the group disabled security software on at least 40 hosts within roughly two hours. Attackers then deployed ransomware to at least 33 systems.

Warlock also used a bring-your-own-vulnerable-driver, or BYOVD, technique involving a vulnerable signed K7RKScan driver affected by CVE-2025-1055.

The driver allowed attackers to disable antivirus and endpoint detection and response tools before launching the ransomware payload.

Warlock can spread ransomware across the network

Attackers staged the ransomware payload inside the domain SYSVOL share, which could allow them to distribute malware across a network through logon scripts or Group Policy.

Warlock also installed Visual Studio Code Insiders as a service and used its built-in tunneling functionality to maintain remote access to compromised systems.

The group additionally used the open-source NetExec framework for Active Directory enumeration, credential spraying, and remote command execution.

Ransomware launches after security tools go offline

Warlock launched its ransomware almost immediately after disabling security software on individual systems, reducing the time defenders had to respond.

Researchers warn that ToolShell and other SharePoint vulnerabilities remain viable initial-access methods for ransomware groups targeting enterprise and critical infrastructure environments.

The campaign adds to growing concerns over attacks against Microsoft environments. Microsoft recently said attackers are beating defenders in the AI race, while the company’s X account was hacked in a $Clippy crypto scam.

Separately, researchers recently found that GitHub repositories leaked more than 543,000 valid credentials.

Via BleepingComputer

More about the topics: Cybersecurity, Microsoft Sharepoint, Sharepoint

Readers help support Windows Report. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more

User forum

0 messages