Cybersecurity

Warlock Group Exploits SharePoint Vulnerabilities to Attack Water Facilities and a Telecommunications Operator

The China-linked Warlock ransomware group exploited Microsoft SharePoint vulnerabilities to breach a water facility, a telecommunications operator, a regional government entity, and a university, before disabling security tools and deploying ransomware on dozens of devices.

2026-10-02
3 min read
22 views
certi.news Editorial Team
Warlock Group Exploits SharePoint Vulnerabilities to Attack Water Facilities and a Telecommunications Operator

The China-linked Warlock ransomware group targeted a water facility, a telecommunications operator, a regional government entity, and a university, exploiting vulnerabilities in on-premises Microsoft SharePoint deployments to gain initial access to networks. Over the past two months, the attacks have focused on Portuguese- and Spanish-speaking countries in Europe, Africa, and Latin America.

The group emerged in June 2025 and gained prominence a month later when it exploited a series of SharePoint zero-day vulnerabilities known as ToolShell, including CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771. Microsoft later observed the state-backed groups Linen Typhoon and Violet Typhoon, along with a ransomware actor tracked by the company as Storm-2603, using these exploits.

Disabling Protection Before Encrypting Devices

Symantec identifies the attacker as Longlegs and attributes the development of the Warlock ransomware to the group. In an incident that began on July 22, the attacker deployed a tool that disabled security software on at least 40 devices within approximately two hours, then ran Warlock on at least 33 devices.

After the breach, the attacker dropped a web shell capable of operating across multiple SharePoint versions. In some attacks attributed to Longlegs, the attackers used a BYOVD technique, or bring your own vulnerable driver, to deploy a tool that kills antivirus programs and EDR solutions through the signed K7RKScan driver, which contains the CVE-2025-1055 vulnerability.

Legitimate Tools to Expand the Attack

Analysis of the July 22 incident showed that the attacker began reconnaissance two days after initial access, then deleted what appeared to be temporary files or preparation artifacts. The ransomware payload was placed in the SYSVOL share, an area replicated across all domain controllers, enabling the file to be pushed for execution through a logon script or a network-wide Group Policy object.

The attacker also installed the main executable file of a Visual Studio Code Insiders build as a service, taking advantage of VS Code's built-in tunneling feature to connect remotely to compromised devices. On one system, researchers found the open-source security testing framework NetExec, which was used to enumerate Active Directory, test credentials, and execute commands remotely.

Why Does This Matter?

The campaign shows that a SharePoint breach is not the end of the access phase, but can quickly turn into a widespread attack within the corporate environment using administrative tools and trusted storage locations. In the incident analyzed, encryption began on July 31 and appeared almost immediately after protection was disabled on each targeted device.

Symantec and Carbon Black warn that ToolShell and other SharePoint vulnerabilities remain effective access paths more than a year after Warlock emerged. Therefore, the indicators of compromise for files and infrastructure that the researchers attached to their report are of immediate importance to organizations operating SharePoint on-premises, while details about the group's attribution and connection to China remain based on researchers' assessments rather than a public acknowledgment by the attacking entity.

News source
BleepingComputer
Open original source ↗
c
Author

certi.news Editorial Team

In the same category

You may also like

View all news