Warlock Hits SharePoint, Then Strikes
Symantec says the China-linked group behind Warlock ransomware disabled defenses on dozens of hosts within hours of exploiting SharePoint flaws.
Symantec’s threat hunters have tied a run of intrusions against a water utility, a telecom provider, a regional government body, and a university to a single ransomware operation that uses SharePoint flaws as its way in. The actor behind the attacks, which Symantec calls Longlegs and credits with developing the Warlock ransomware, moved from initial access to encryption in a sequence measured in days, not weeks. The intrusions reviewed by the researchers unfolded over the past two months.
The same actor is tracked by Microsoft as Storm-2603. The four victim organizations span sectors whose downtime tends to be felt outside their own networks, and they were hit through flaws in on-premises SharePoint deployments that had not been fully closed off.
Who Warlock Is And When It Appeared
Warlock emerged in June 2025. A month later it drew attention after exploiting a chain of zero-day vulnerabilities in Microsoft SharePoint that became known as ToolShell. Those flaws are catalogued as CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771.
By August, Microsoft observed state-backed hacking groups Linen Typhoon and Violet Typhoon using ToolShell exploits in attacks, along with a ransomware threat actor the company tracks as Storm-2603. Symantec attributes the same activity to Longlegs and says the group is responsible for developing the Warlock ransomware.
Over the past two months, the actor’s focus has fallen on Portuguese- and Spanish-speaking countries across Europe, Africa, and Latin America, according to the researchers.
The Two-Hour Push To Disable Defenses
Symantec’s account of one intrusion, which began on July 22, describes a tool deployed to disable protection software on “at least 40 hosts within about two hours.” The attacker then launched Warlock ransomware on at least 33 hosts.
Entry typically came through vulnerabilities in on-premises SharePoint deployments. Once inside, the attacker dropped a web shell built to work across multiple SharePoint versions, giving a durable foothold that did not depend on a single server build.
Symantec and Carbon Black researchers say that in some attacks attributed to Longlegs, an AV/EDR-killing tool was deployed using the bring your own vulnerable driver (BYOVD) technique. The driver in question is a signed K7RKScan driver vulnerable to CVE-2025-1055.
“a known method of pushing a payload out for execution by a logon script or Group Policy object across an entire network at once, rather than one host at a time”
— Symantec researchers
Staging The Payload In SYSVOL
The ransomware payload was staged in the domain’s SYSVOL share, a location that stores public files and is replicated across every domain controller. The researchers describe this as a known method of pushing a payload out for execution by a logon script or Group Policy object across an entire network at once, rather than one host at a time.
That choice matters for how quickly the attack scaled. SYSVOL replication means a single placement can reach every domain controller in the environment without the attacker touching each host individually.
Alongside the payload, the main executable for Visual Studio Code Insiders was installed as a service during the attack, enabling remote connections to compromised machines through VS Code’s built-in tunneling capability.
Reconnaissance And Deleted Artifacts
Analysis of the July 22 intrusion showed that two days after gaining initial access, the threat actor carried out reconnaissance activity and deleted what appeared to be staging artifacts.
On one of the systems, the researchers found the open-source penetration testing framework NetExec, which the attacker used for Active Directory enumeration, credential spraying, and remote command execution.
The final stage came on July 31, after the AV/EDR killer was deployed. According to Symantec, Warlock ransomware appeared almost as soon as protection was disabled on each host.
What The Researchers Found In The Report
Symantec and Carbon Black published their findings with a set of indicators of compromise covering files and infrastructure tied to the attacks. The researchers also warn that ToolShell and other SharePoint vulnerabilities remain viable initial access vectors, more than a year after Warlock first emerged exploiting SharePoint flaws.
- In one intrusion that began July 22, a tool disabled protection software on at least 40 hosts within about two hours.
- Warlock ransomware was launched on at least 33 hosts.
- The final stage of that attack occurred on July 31.
- ToolShell covers four SharePoint CVEs: CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771.
- The BYOVD technique relied on a signed K7RKScan driver vulnerable to CVE-2025-1055.
- Warlock first emerged in June 2025.
The ToolShell Timeline
The chain of flaws that gave the group its opening was not new when these intrusions occurred. Warlock’s emergence in June 2025 was followed a month later by its exploitation of the ToolShell chain, which is how the group became widely known.
In August, Microsoft’s observations added state-backed groups to the picture: Linen Typhoon and Violet Typhoon were seen using ToolShell exploits, alongside the actor Microsoft tracks as Storm-2603. That overlap put the same SharePoint flaws in the hands of both espionage-oriented and financially motivated operators.
Symantec’s more recent findings place a different actor name — Longlegs — on the same activity and tie the Warlock ransomware’s development to that group.
Why The SharePoint Path Still Works
The researchers’ warning is specific: ToolShell and other SharePoint vulnerabilities remain viable initial access vectors. That assessment comes more than a year after Warlock first emerged exploiting SharePoint flaws, which means the entry point has outlasted the group’s initial notoriety.
On-premises SharePoint deployments are the common thread. The web shell the attacker drops is designed to function across multiple SharePoint versions, which reduces the attacker’s dependence on any single target’s configuration.
The July 22 intrusion shows the sequence from there: reconnaissance two days after entry, deletion of staging artifacts, a BYOVD-based AV/EDR killer, payload staged in SYSVOL, VS Code Insiders installed as a service for tunneling, NetExec for Active Directory work, and encryption on July 31.
What The Targeting Suggests For Defenders
The victim list — a water utility, a telecom provider, a regional government body, and a university — points to organizations where an outage is felt beyond the corporate network. That is a pattern worth reading carefully, but it is not proof of a broader campaign beyond these four sectors as reported.
For defenders, the practical questions raised by Symantec’s account are narrower than a general call to patch. The intrusion moved from a disabled defense layer to encryption quickly, and the tools involved — a signed vulnerable driver, a developer tool installed as a service, a penetration testing framework, and SYSVOL as a distribution point — are all legitimate components of a Windows environment when used as intended.
That suggests detection efforts may need to focus on how those components are used rather than whether they exist. A signed K7RKScan driver loading in an environment that has no reason to run it, VS Code Insiders registered as a service, or unexpected changes to SYSVOL are the kinds of signals the report makes visible.
The researchers’ own conclusion is that the SharePoint entry point is not closed. Organizations that run on-premises SharePoint and have not addressed the ToolShell CVEs remain exposed to the same initial access route that put Longlegs inside these four victims.
Sources
- BleepingComputer Original source
Continue Reading
Frontline Education breach hits school staff
Edtech vendor Frontline Education says attackers exploited a third-party software flaw to access employee data including Social Security numbers.
Nvidia chip smuggling case carries 50-year max
A California business owner faces charges of allegedly exporting around $300 million in advanced Nvidia hardware to China without required licenses.
Antino Backdoor Hides C2 in Outlook, OneDrive
A China-nexus actor is using Microsoft 365 mailboxes and cloud storage as dead drops to command a Rust-compiled Windows backdoor, Talos reports.