Warlock ransomware breach SharePoint in water, telecom operator attacks
The Warlock ransomware group, linked to China, has targeted multiple organizations including a water utility, telecom provider, regional government, and university by exploiting Microsoft SharePoint vulnerabilities. The group uses a chain of zero-day SharePoint vulnerabilities known as ToolShell for initial access. After gaining access, they deploy tools to disable endpoint protection on numerous hosts and then launch ransomware. The attackers also use techniques such as deploying web shells, using vulnerable signed drivers to kill AV/EDR, and leveraging Visual Studio Code's tunneling for remote access. The ransomware payload is distributed via SYSVOL shares to execute across the network. These SharePoint vulnerabilities remain exploitable more than a year after initial discovery.
AI Analysis
Technical Summary
Warlock ransomware, attributed to the China-linked group Longlegs, exploits a chain of zero-day Microsoft SharePoint vulnerabilities (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, CVE-2025-53771) known as ToolShell to gain initial access to targeted networks. The group targets organizations in Portuguese and Spanish-speaking countries across Europe, Africa, and Latin America. After initial compromise, Warlock operators deploy a web shell compatible with multiple SharePoint versions and use a signed vulnerable driver (CVE-2025-1055) to disable AV/EDR protections on at least 40 hosts within hours. The ransomware payload is staged in the SYSVOL share to enable network-wide execution via Group Policy or logon scripts. Attackers also install Visual Studio Code Insiders as a service to enable remote control via VS Code tunneling and use tools like NetExec for Active Directory enumeration and credential spraying. Despite being known for over a year, ToolShell and related SharePoint vulnerabilities remain active attack vectors.
Potential Impact
Successful exploitation allows the attacker to gain initial access to corporate networks by compromising on-premises SharePoint servers. This access enables deployment of tools that disable endpoint protection on dozens of hosts, facilitating widespread ransomware deployment. The ransomware encrypts data across multiple hosts, potentially disrupting critical services in targeted sectors such as water utilities, telecommunications, government, and education. The use of SYSVOL for payload distribution enables rapid propagation across domain controllers and networked systems, increasing the scale and impact of the attack.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance on the ToolShell SharePoint vulnerabilities and CVE-2025-1055. Organizations should prioritize applying official Microsoft security updates for SharePoint and related components once available. Until patches are applied, restrict access to SharePoint servers, monitor for signs of web shell deployment, and review Group Policy and SYSVOL shares for unauthorized changes. Since the threat actor uses a signed vulnerable driver to disable endpoint protection, ensure endpoint security solutions are updated to detect and block such techniques. Follow vendor guidance closely as Microsoft manages remediation for cloud services, but on-premises SharePoint deployments require direct patching.
Warlock ransomware breach SharePoint in water, telecom operator attacks
Description
The Warlock ransomware group, linked to China, has targeted multiple organizations including a water utility, telecom provider, regional government, and university by exploiting Microsoft SharePoint vulnerabilities. The group uses a chain of zero-day SharePoint vulnerabilities known as ToolShell for initial access. After gaining access, they deploy tools to disable endpoint protection on numerous hosts and then launch ransomware. The attackers also use techniques such as deploying web shells, using vulnerable signed drivers to kill AV/EDR, and leveraging Visual Studio Code's tunneling for remote access. The ransomware payload is distributed via SYSVOL shares to execute across the network. These SharePoint vulnerabilities remain exploitable more than a year after initial discovery.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Warlock ransomware, attributed to the China-linked group Longlegs, exploits a chain of zero-day Microsoft SharePoint vulnerabilities (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, CVE-2025-53771) known as ToolShell to gain initial access to targeted networks. The group targets organizations in Portuguese and Spanish-speaking countries across Europe, Africa, and Latin America. After initial compromise, Warlock operators deploy a web shell compatible with multiple SharePoint versions and use a signed vulnerable driver (CVE-2025-1055) to disable AV/EDR protections on at least 40 hosts within hours. The ransomware payload is staged in the SYSVOL share to enable network-wide execution via Group Policy or logon scripts. Attackers also install Visual Studio Code Insiders as a service to enable remote control via VS Code tunneling and use tools like NetExec for Active Directory enumeration and credential spraying. Despite being known for over a year, ToolShell and related SharePoint vulnerabilities remain active attack vectors.
Potential Impact
Successful exploitation allows the attacker to gain initial access to corporate networks by compromising on-premises SharePoint servers. This access enables deployment of tools that disable endpoint protection on dozens of hosts, facilitating widespread ransomware deployment. The ransomware encrypts data across multiple hosts, potentially disrupting critical services in targeted sectors such as water utilities, telecommunications, government, and education. The use of SYSVOL for payload distribution enables rapid propagation across domain controllers and networked systems, increasing the scale and impact of the attack.
Defensive Guidance
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance on the ToolShell SharePoint vulnerabilities and CVE-2025-1055. Organizations should prioritize applying official Microsoft security updates for SharePoint and related components once available. Until patches are applied, restrict access to SharePoint servers, monitor for signs of web shell deployment, and review Group Policy and SYSVOL shares for unauthorized changes. Since the threat actor uses a signed vulnerable driver to disable endpoint protection, ensure endpoint security solutions are updated to detect and block such techniques. Follow vendor guidance closely as Microsoft manages remediation for cloud services, but on-premises SharePoint deployments require direct patching.
Technical Details
- Classification
- {"confidence":0.69,"severitySource":"heuristic","classifier":"rss-v2"}
Threat ID: 6abffbf6a43b0b3b89ec01ff
Added to database: 10/02/2026, 18:46:14 UTC
Last enriched: 10/02/2026, 18:46:21 UTC
Last updated: 10/03/2026, 03:03:33 UTC
Views: 14
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.