Cybersecurity Flash Notices

Warlock Ransomware Campaign β€” China-Linked Group Targets Water, Telecom & Government via SharePoint

Written by Marketing | Oct 6, 2026, 8:41:14β€―PM

πŸ”΄ CRITICAL β€” ACTIVE RANSOMWARE CAMPAIGN TARGETING CRITICAL INFRASTRUCTURE: The China-linked ransomware group Warlock has conducted a multi-month campaign exploiting Microsoft SharePoint vulnerabilities (ToolShell zero-days) to target critical infrastructure organizations including water utilities, telecom providers, regional government bodies, and universities across Spanish and Portuguese-speaking countries. The group deploys EDR/AV-killing tools via BYOVD techniques and executes Warlock ransomware across entire networks. In a single documented intrusion (July 22–31, 2026), the group encrypted at least 33 hosts after disabling endpoint protection on 40+ systems.

Organizations with unpatched on-premises SharePoint deployments in water, energy, telecom, and government sectors remain at critical risk of network-wide encryption and operational disruption.

 

overview

The China-linked ransomware group Warlock (also tracked as Longlegs by Symantec) is conducting an active, multi-month campaign targeting critical infrastructure organizations across Spanish and Portuguese-speaking countries in Europe, Africa, and Latin America. The group exploits unpatched Microsoft SharePoint vulnerabilities (ToolShell chain: CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, CVE-2025-53771) to gain initial access to victim networks, then deploys web shells, EDR/AV-killing tools, and Warlock ransomware for network-wide encryption. Documented targets include water utilities, telecom providers, regional government bodies, and universities.

In a single intrusion documented by Symantec and Carbon Black, the group successfully encrypted at least 33 hosts across a regional government entity after establishing persistence and disabling security controls on 40+ hosts within approximately two hours. The group emerged in June 2025 and gained prominence in July 2025 after leveraging the same SharePoint zero-day exploits used by state-backed groups Linen Typhoon and Violet Typhoon. Organizations with on-premises or hybrid SharePoint deployments in critical infrastructure sectors remain at significant risk of operational disruption, data theft, and ransom extortion.

 

attack campaign overview

Threat Group & Attribution:

Warlock is a China-linked ransomware group that emerged in June 2025. Symantec tracks a related threat actor with similar TTPs as Longlegs and credits them with developing the Warlock ransomware payload. The group has demonstrated access to zero-day exploits for Microsoft SharePoint and sophisticated EDR evasion techniques. The group's targeting patterns (geographic focus on Spanish/Portuguese-speaking organizations, critical infrastructure vertical) suggest potential state sponsorship or coordination with Chinese government cyber operations.

Initial Access Vector β€” SharePoint ToolShell Vulnerabilities:

Warlock gains initial access by exploiting a chain of four zero-day vulnerabilities in Microsoft SharePoint, collectively tracked as ToolShell. These vulnerabilities allow unauthenticated remote attackers to execute arbitrary code on SharePoint servers. Microsoft confirmed that state-backed groups Linen Typhoon and Violet Typhoon were exploiting the same ToolShell chain in mid-to-late 2025. The vulnerabilities affect on-premises SharePoint deployments and hybrid configurations where SharePoint front-end servers are accessible from the Internet.

CVE Details (ToolShell Chain):

  • CVE-2025-49704 β€” Remote Code Execution (RCE)
  • CVE-2025-49706 β€” Remote Code Execution (RCE)
  • CVE-2025-53770 β€” Remote Code Execution (RCE)
  • CVE-2025-53771 β€” Remote Code Execution (RCE)

Post-Exploitation Workflow (Documented July 22–31, 2026):

  1. Initial Compromise (Day 0 β€” July 22): Attacker exploits SharePoint vulnerability chain to execute code on server. Web shell deployed to enable persistent backdoor access across multiple SharePoint versions.
  2. Reconnaissance (Day 2 β€” July 24): Attacker engages in Active Directory enumeration and network discovery using legitimate tools and custom exploits. Attacker identifies critical systems, domain structure, and security software in use. Staging artifacts cleaned up to minimize detection.
  3. EDR/AV Killing (Day 9 β€” July 31, ~2 hours): Attacker deploys EDR/AV-killing tool via Bring Your Own Vulnerable Driver (BYOVD) technique using a signed K7RKScan driver vulnerable to CVE-2025-1055. The killing tool successfully disables endpoint protection on at least 40 hosts within approximately two hours.
  4. Ransomware Deployment (Day 9 β€” July 31): Immediately after security controls disabled, Warlock ransomware deployed to at least 33 hosts across the network. Ransomware executes with high privileges (thanks to compromised domain controllers and disabled EDR). File encryption begins on all targeted systems simultaneously.
  5. Data Exfiltration & Extortion (Ongoing): Attacker steals sensitive data from shared drives, file servers, and backups during encryption process. Ransom note displayed to affected users. Attacker demands payment in cryptocurrency with threat of public data leak.

Key Technical Capabilities:

  • BYOVD EDR Killer: CVE-2025-1055 in K7RKScan (a signed, legitimate driver) exploited to escalate privileges and disable kernel-mode EDR/AV protections. Highly effective against modern endpoint detection solutions.
  • VS Code Insiders Tunneling: Visual Studio Code Insiders installed as Windows service to enable remote tunneling capability. Provides persistent, interactive shell access to compromised systems even if primary backdoor detected/removed. Difficult to detect due to VS Code's legitimacy.
  • NetExec Framework: Open-source post-exploitation framework deployed for Active Directory enumeration, credential spraying, and lateral movement. Enables rapid privilege escalation and network-wide compromise.
  • SYSVOL Payload Staging: Ransomware payload staged in domain's SYSVOL share (replicated to every domain controller automatically). Enables single-point deployment to entire network via Group Policy Object or logon script execution. Highly efficient for network-wide encryption.
  • Warlock Ransomware Payload: Custom-developed ransomware that encrypts files across compromised hosts. High speed encryption (33+ hosts encrypted within hours after EDR disabled). Sophisticated ransom UI and data leak infrastructure.

Geographic Focus & Targeting:

Over the past two months (August–September 2026), Warlock has focused exploitation efforts on countries with Portuguese and Spanish-speaking populations across Europe (Portugal, Spain), Africa (Angola, Mozambique, Cape Verde), and Latin America (Mexico, Argentina, Chile, Colombia, etc.). Targeting suggests either financial motivation (critical infrastructure generates larger ransom payouts) or geopolitical targeting aligned with Chinese interests in Latin America and Africa.

 

threat actor and attribution

Primary Attribution: Warlock / Longlegs (China-linked, ransomware variant of state-linked APT group)

Evidence of Attribution:

  • Access to zero-day SharePoint exploits (typically indicative of state-level resources)
  • Sophisticated BYOVD EDR evasion techniques
  • Coordination with other Chinese-attributed groups (Linen Typhoon, Violet Typhoon) sharing same ToolShell exploits
  • Strategic targeting of critical infrastructure in geopolitically significant regions (Latin America, Africa)
  • Development of custom ransomware payload (not off-the-shelf malware)
  • Geographic focus on Spanish/Portuguese-speaking countries aligns with Chinese strategic interests

Modus Operandi: Warlock appears to operate as a state-sponsored or state-affiliated ransomware group, providing both espionage capabilities (via initial access and data exfiltration) and deniable revenue generation (ransomware). Similar to Evil Corp / LockBit model of mixing APT activities with criminal ransomware operations.

 

potential impact

  • Operational Disruption: Complete network-wide encryption of critical systems (water treatment, power distribution, telecommunications infrastructure) can halt essential services and endanger public safety. Recovery time measured in days to weeks even with backups.
  • Critical Infrastructure Failure: Water utilities losing operational control of treatment/distribution systems; telecom providers losing service capability; government agencies losing administrative function; universities losing research and student data.
  • Data Exfiltration & Extortion: Attacker steals sensitive personal information (citizen IDs, health records, financial data), intellectual property, research data, and operational secrets. Threat of public disclosure used for extortion in addition to ransom demand.
  • Public Safety Risk: Water utilities unable to treat/distribute water; power systems unable to regulate grid; emergency services unable to coordinate response. Real-world impact to public health and safety.
  • Supply Chain Disruption: Critical infrastructure unable to operate; cascading impact to dependent services and private sector customers relying on water, power, telecom infrastructure.
  • Financial Extortion: Significant ransom demands ($millions typical for critical infrastructure). Pressure to pay before operations recover. Funds sent to Chinese state-linked financial channels.
  • National Security Implications: State-sponsored ransomware against critical infrastructure indicates escalated threat level and potential precursor to kinetic conflict or larger espionage campaigns. Compromised infrastructure could serve as launch point for future attacks.
  • Regulatory/Compliance Violations: Critical infrastructure failure triggers mandatory breach notifications, regulatory investigations, and potential sanctions. Organizations may face operational restrictions or forced system upgrades.

 

indicators of compromise

Network-Based Indicators:

  • HTTP/HTTPS requests to SharePoint servers with payloads matching ToolShell exploit patterns (unusual URL encoding, script injection attempts)
  • Unexpected web shell files in SharePoint directories (*.aspx, *.ashx files with obfuscated names or recently created)
  • Outbound HTTPS connections from SharePoint servers to attacker infrastructure (C2 communications)
  • Mass credential authentication attempts from compromised domain accounts (credential spraying activity)
  • Unusual Group Policy Object (GPO) modifications or Group Policy updates pushing executable payloads
  • SYSVOL share accessed at unusual times or by unexpected accounts; unexpected executable files in \\domain\SYSVOL\
  • NetExec/CrackMapExec framework communication patterns (SMB reconnaissance, LDAP enumeration)

Endpoint-Based Indicators:

  • Visual Studio Code Insiders process running as system service (unusual execution context)
  • K7RKScan.sys loaded in kernel memory (vulnerable driver used for BYOVD)
  • EDR/AV process termination or service stoppage (disabling of protection software)
  • Warlock ransomware executable in memory or on disk (file encryption process running)
  • Ransom note file creation (.txt, .html files with Warlock branding/payment instructions)
  • Mass file encryption activity (.encrypted, .locked file extensions)
  • Suspicious process execution: powershell.exe, cmd.exe spawning from unusual parents (w3wp.exe from SharePoint, svchost.exe, etc.)
  • Registry modifications disabling Windows Defender, security features, or software updates

Log-Based Indicators:

  • SharePoint logs showing unusual HTTP requests with ToolShell-like patterns (encoding oddities, script injection)
  • Active Directory logs showing mass failed/successful authentication attempts from single source (credential spraying)
  • Event log showing EDR/AV service stop events without administrative action
  • Group Policy application logs showing unexpected GPO modifications or policy push from unauthorized source
  • Windows Defender/Security logs showing disabled security features or malware quarantine deletions
  • File audit logs showing mass file access/modification by system service accounts or unexpected users

 

monitoring and telemetry

  • SharePoint Web Log Monitoring: Enable comprehensive logging of all HTTP/HTTPS requests to SharePoint servers. Monitor for unusual request patterns, script injection attempts, path traversal sequences, and anomalous URL encoding. Deploy WAF rules detecting ToolShell exploit attempts. Alert on any requests matching known PoC patterns.
  • EDR/XDR Monitoring: Monitor for EDR/AV process termination events (unexpected service stops, driver unload events). Alert on Visual Studio Code service installation or execution in unusual contexts. Monitor for vulnerable driver (K7RKScan.sys) loading in kernel memory. Track suspicious process chains originating from SharePoint (w3wp.exe spawning powershell, cmd.exe, executable downloads).
  • Active Directory Monitoring: Monitor for mass failed/successful authentication attempts (credential spraying attempts). Alert on unusual account escalation or privilege group additions. Track domain controller replication traffic (DCSync activity). Monitor for unusual SYSVOL modifications or executable staging in SYSVOL share.
  • File Integrity Monitoring (FIM): Monitor critical SharePoint directories for new/modified files (especially .aspx, .ashx web shells). Monitor SYSVOL share for executable file creation or modifications. Track rapid file modification events indicating encryption activity. Alert on files created with ransomware-typical extensions.
  • Network Telemetry: Monitor for outbound HTTPS connections from SharePoint servers to unknown/suspicious IPs. Track unusual SMB traffic between servers (lateral movement). Monitor for Group Policy replication traffic to domain controllers. Alert on any connections to known malicious IPs or C2 infrastructure.
  • Backup & Recovery Monitoring: Monitor for suspicious access to backup systems, backup deletion events, or backup service disabling. Alert on failed backup jobs or backup integrity issues. Track shadow copy deletion attempts (common ransomware pre-encryption activity).
  • Threat Intelligence Integration: Subscribe to Symantec, Carbon Black, and vendor threat feeds for Warlock/Longlegs IOCs and exploitation signatures. Monitor for detection rules matching ToolShell exploits or BYOVD CVE-2025-1055 exploitation.

 

compliance impact

PCI DSS: Requirement 6.2 (patch management) β€” critical vulnerabilities in systems handling payment data require urgent patching. Ransomware attack on any system handling cardholder data triggers breach notification and regulatory reporting. Water utilities and telecom providers handling payment processing must ensure SharePoint systems are patched or segmented from payment networks.

HIPAA: Healthcare providers and insurance companies handling ePHI through SharePoint systems must patch immediately. Ransomware encryption of ePHI triggers breach notification to HHS and affected individuals under 45 CFR Β§164.410. Unpatched SharePoint represents material breach risk.

GDPR: Article 32 (security of processing) requires appropriate technical measures. SharePoint vulnerability indicates control failure. Article 33 (breach notification) requires notification to authorities within 72 hours if personal data exposure confirmed. Public administration and utilities in EU must comply with GDPR breach notification if EU citizen data exposed.

NIST CSF: Protect (PR.IP, PR.MA) β€” patching and vulnerability management failures. Detect (DE.CM) β€” monitoring for exploitation attempts. Respond (RS) β€” ransomware response procedures. Organizations subject to federal contractor requirements must remediate immediately and document response.

ISO/IEC 27001: A.12.2 (change management) β€” patches managed through controlled process. A.12.6 (vulnerability management) β€” critical vulnerabilities require immediate remediation. A.14.2.1 (information security requirements) for critical infrastructure service providers.

Critical Infrastructure Regulations: Utilities and telecom providers subject to CISA cybersecurity requirements, NERC CIP standards, or regional critical infrastructure protection mandates must report ransomware incidents. Unpatched known-exploited vulnerabilities may trigger regulatory sanctions.

 

recommendations

IMMEDIATE ACTIONS (Today β€” within 24 hours):

  • Patch SharePoint Immediately: All organizations running Microsoft SharePoint Server on-premises or in hybrid deployments must apply latest security patches immediately. Microsoft released updates addressing ToolShell vulnerabilities (CVE-2025-49704, 49706, 53770, 53771) in late 2025. Verify patch versions installed and deploy to all SharePoint servers within 24 hours.
  • Inventory SharePoint Deployments: Document all SharePoint Server instances across organization. Record version numbers, deployment location (on-premises, hybrid, online-only), internet exposure status, and business criticality. Prioritize patching for internet-facing and hybrid deployments first.
  • Threat Hunt for Current Exploitation: Search SharePoint logs for indicators of ToolShell exploitation attempts or successful compromise. Look for suspicious HTTP requests with unusual encoding or script injection patterns. Review web shell IOCs across SharePoint application directories. Search for unexpected .aspx or .ashx files recently created in SharePoint directories.
  • EDR Review & Hardening: Verify EDR/AV agents are actively running on all systems. Check for known vulnerable drivers (K7RKScan.sys) that could be exploited via BYOVD. Review EDR detection rules for ransomware and post-exploitation activity. Test EDR ability to detect Visual Studio Code service installation.
  • Backup Verification: Verify backup systems are functional, isolated from production network, and protected from encryption. Test backup restoration procedures. Ensure backup services cannot be disabled by standard user/service accounts.
  • Disable Legacy Authentication: Disable basic authentication on SharePoint services. Enforce MFA for all remote access to SharePoint administration. Restrict SharePoint management interface access to trusted IPs only.

SHORT-TERM ACTIONS (1-3 days):

  • Deploy Detection Rules: Deploy IDS/IPS signatures detecting ToolShell exploitation attempts. Deploy endpoint detection rules for BYOVD exploitation patterns, EDR-killing tool behavior, and ransomware execution. Subscribe to threat intelligence feeds with Warlock/Longlegs IOCs and detection signatures.
  • Network Segmentation: Isolate SharePoint servers from general user networks using VLANs or network segmentation. Restrict lateral movement from SharePoint compromises to domain controllers and file servers. Implement network access controls limiting domain controller replication to authorized hosts only.
  • Forensic Investigation (If Compromised): If exploitation evidence found, activate incident response. Preserve compromised SharePoint server for forensic analysis. Identify timeline of attacker activity, lateral movement paths, and data theft scope. Preserve backups and web server logs for evidence.
  • Credential Review: Force password reset for any domain accounts that accessed compromised SharePoint servers. Audit privileged account activity for suspicious commands or lateral movement. Review domain admin group membership for unauthorized additions.
  • Cloud Migration Planning (If Applicable): For organizations with on-premises SharePoint, begin planning migration to SharePoint Online (Microsoft 365). Online deployments eliminate on-premises attack surface and receive automatic security patches from Microsoft.

ONGOING GOVERNANCE:

  • Patch Management Acceleration: Establish expedited patching process for critical infrastructure applications. SharePoint and other internet-facing services must be patched within 48 hours of release. Test patches in staging environment before production deployment.
  • Ransomware Preparedness Program: Conduct ransomware response tabletop exercises. Test backup and recovery procedures quarterly. Establish incident response team and communication procedures. Develop public communications strategy for potential ransomware incident impacting critical services.
  • Continuous Monitoring: Maintain persistent monitoring of SharePoint servers for exploitation attempts and post-exploitation indicators. Deploy file integrity monitoring on SYSVOL and critical file shares. Monitor for suspicious process execution and Group Policy modifications.
  • Vendor Vulnerability Tracking: Subscribe to Microsoft security bulletins and CISA Known Exploited Vulnerabilities list. Establish process for rapid patch evaluation and prioritization. Maintain documented inventory of known-exploited vulnerabilities affecting your infrastructure.
  • Supply Chain Security: For critical infrastructure utilities and telecom providers, coordinate ransomware response procedures with upstream/downstream partners. Share IOCs and threat intelligence. Establish communication procedures for coordinated incident response affecting interdependent services.

 

SUPPORTING DOCUMENTATION