Warlock Ransomware Uses SharePoint Flaws to Breach Networks
Warlock ransomware is targeting critical organizations, including water, telecom, government, and education entities, with attackers using SharePoint vulnerabilities to gain initial access.
Warlock targets critical organizations
The China-linked ransomware group Warlock has targeted a water utility, telecom provider, regional government body, and university.
Recent attacks have focused largely on Portuguese- and Spanish-speaking organizations across Europe, Africa, and Latin America.
Warlock, which Symantec also tracks as Longlegs, first gained attention after exploiting the ToolShell SharePoint vulnerability chain to breach enterprise networks.
SharePoint flaws give attackers initial access
Warlock typically exploits vulnerabilities in on-premises SharePoint servers before deploying a web shell that works across multiple SharePoint versions.
In one July attack, the group disabled security software on at least 40 hosts within roughly two hours. Attackers then deployed ransomware to at least 33 systems.
Warlock also used a bring-your-own-vulnerable-driver, or BYOVD, technique involving a vulnerable signed K7RKScan driver affected by CVE-2025-1055.
The driver allowed attackers to disable antivirus and endpoint detection and response tools before launching the ransomware payload.
Warlock can spread ransomware across the network
Attackers staged the ransomware payload inside the domain SYSVOL share, which could allow them to distribute malware across a network through logon scripts or Group Policy.
Warlock also installed Visual Studio Code Insiders as a service and used its built-in tunneling functionality to maintain remote access to compromised systems.
The group additionally used the open-source NetExec framework for Active Directory enumeration, credential spraying, and remote command execution.
Ransomware launches after security tools go offline
Warlock launched its ransomware almost immediately after disabling security software on individual systems, reducing the time defenders had to respond.
Researchers warn that ToolShell and other SharePoint vulnerabilities remain viable initial-access methods for ransomware groups targeting enterprise and critical infrastructure environments.
The campaign adds to growing concerns over attacks against Microsoft environments. Microsoft recently said attackers are beating defenders in the AI race, while the company’s X account was hacked in a $Clippy crypto scam.
Separately, researchers recently found that GitHub repositories leaked more than 543,000 valid credentials.
Via BleepingComputer
Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more
User forum
0 messages