**Warlock Ransomware: Exploiting SharePoint Vulnerabilities for Devastating Attacks**
A recent surge in high-profile attacks has highlighted the alarming trend of cybersecurity threats targeting vulnerable organizations worldwide. One such threat actor, the China-linked ransomware group Warlock, has been making headlines for its sophisticated attacks on water utilities, telecom providers, regional government bodies, and universities. What's more disturbing is that Warlock has been exploiting SharePoint vulnerabilities to gain initial access, leaving organizations scrambling to patch their defenses.
Over the past two months, Warlock has been particularly active in countries speaking Portuguese and Spanish across Europe, Africa, and Latin America. The gang's emergence in June 2025 was marked by its ability to exploit a chain of zero-day vulnerabilities in Microsoft SharePoint known as ToolShell (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771). By August, Microsoft had observed state-backed hacking groups Linen Typhoon and Violet Typhoon using ToolShell exploits in attacks, along with a ransomware threat actor the company tracks as Storm-2603.
**A Recipe for Disaster: Exploiting SharePoint Vulnerabilities**
Warlock's attacks typically begin with the exploitation of vulnerabilities in on-premises SharePoint deployments. Once access is gained, the attacker drops a web shell designed to function across multiple SharePoint versions. This web shell is then used to disable protection software on compromised hosts, paving the way for the deployment of the Warlock ransomware.
In one notable incident, the threat actor deployed a tool that disabled protection software on at least 40 hosts within a matter of hours. The attacker then launched Warlock ransomware on at least 33 hosts. This rapid pace of attack underscores the importance of patching SharePoint vulnerabilities and implementing robust security measures to prevent initial access.
**The BYOVD Technique: A New Vector for Attackers**
Symantec and Carbon Black researchers have identified the use of the bring your own vulnerable driver (BYOVD) technique in some attacks attributed to Longlegs. This technique involves deploying a signed K7RKScan driver vulnerable to CVE-2025-1055. The use of BYOVD underscores the evolving nature of cyber threats and the need for organizations to stay ahead of the curve in terms of threat detection and mitigation.
**Analysis of the Warlock Ransomware Attack**
Analysis of the July 22 intrusion revealed that two days after gaining initial access, the threat actor engaged in reconnaissance activity and deleted staging artifacts. The ransomware payload was staged in the domain's SYSVOL share, a location that stores public files and is replicated across every domain controller. This method of payload deployment is a known tactic used by threat actors to push a payload out for execution by a logon script or Group Policy object across an entire network at once.
During the attack, the main executable file for Visual Studio Code Insiders was installed as a service to enable connecting remotely to compromised machines using VS Code's built-in tunneling capability. The researchers also found the open-source penetration testing framework NetExec, which helped the attacker with Active Directory enumeration, credential spraying, and remote command execution.
**The Warlock Ransomware: A Growing Threat**
The Warlock ransomware has been identified as a growing threat by cybersecurity researchers. The gang's ability to exploit SharePoint vulnerabilities has left organizations scrambling to patch their defenses. The use of BYOVD and the deployment of the AV/EDR killer further underscores the sophistication and evolving nature of this threat.
In conclusion, the Warlock ransomware is a prime example of the devastating attacks that can occur when organizations fail to patch vulnerabilities and implement robust security measures. As the threat landscape continues to evolve, it is essential for organizations to stay ahead of the curve in terms of threat detection and mitigation.
**Indicators of Compromise: A Call to Action**
Symantec and Carbon Black researchers have released a set of indicators of compromise for files and infrastructure used in the attacks. We urge organizations to review these indicators and take immediate action to patch vulnerabilities and implement robust security measures to prevent initial access.
**Build Your Security Blueprint for AI-Powered Attacks**
Join us for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed. Our panel of experts will provide insights and best practices for building a robust security posture in the face of evolving cyber threats.
**Sources:**
* Symantec and Carbon Black Threat Hunters Report * Microsoft Security Blog * Threatpost
**Keywords:** Warlock ransomware, SharePoint vulnerabilities, ToolShell, BYOVD, AV/EDR killer, Longlegs, Storm-2603, Linen Typhoon, Violet Typhoon, Microsoft Exchange, SparroWocky malware, GrayRabbit malware, Chinese hackers, AI-powered attacks.