China-Linked Warlock Ransomware Group Exploits SharePoint, Disables EDR on 40 Hosts
China-linked ransomware group Warlock is targeting water utilities, telecommunications providers, local governments, and universities by exploiting vulnerabilities in on-premises Microsoft SharePoint deployments.
Over the past two months, the attackers appear to have focused on Portuguese- and Spanish-speaking countries across Europe, Africa, and Latin America.
The group emerged in June 2025 and gained notoriety one month later after exploiting a set of Microsoft SharePoint zero-day vulnerabilities known as ToolShell: CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771.
By August, Microsoft had observed state-sponsored groups Linen Typhoon and Violet Typhoon using ToolShell exploits in attacks, along with a ransomware threat actor tracked by Microsoft as Storm-2603.
Warlock attackers deployed an EDR killer on at least 40 hosts
Cybersecurity firm Symantec identified the attackers as Longlegs and attributed the development of Warlock ransomware to the group.
In one breach that began on July 22, the attackers deployed tools that disabled security software on “at least 40 hosts within approximately two hours,” according to researchers. They then launched Warlock ransomware on at least 33 hosts.
The attackers typically gain initial access by exploiting vulnerabilities in on-premises SharePoint servers before deploying a web shell designed to work across multiple SharePoint versions.
Symantec and Carbon Black researchers said that, in some attacks attributed to Longlegs, tools designed to disable antivirus and endpoint detection and response (EDR) software were deployed using bring-your-own-vulnerable-driver (BYOVD) techniques. The attackers used a signed K7RKScan driver vulnerable to CVE-2025-1055.
Analysis of the July 22 intrusion found that, two days after gaining access, the attackers conducted reconnaissance and removed what appeared to be staging artifacts.
Attackers used Visual Studio Code tunneling for remote access
The Warlock ransomware payload was staged in the domain’s SYSVOL share, where public files are stored and replicated to all domain controllers.
This is “a known method for pushing and executing payloads simultaneously across a network, rather than one host at a time, through logon scripts or Group Policy objects,” researchers say.
During the intrusion, the attackers installed the main Visual Studio Code Insiders executable as a service. This enabled remote connections to compromised systems through Visual Studio Code’s built-in tunneling feature.
Researchers also found NetExec on one system. The open-source penetration testing framework can help attackers enumerate Active Directory, spray credentials, and execute commands remotely.
Warlock ransomware deployed after security protections were disabled
The final attack stage occurred on July 31. After deploying the antivirus and EDR killer, the attackers launched Warlock ransomware “almost immediately after protection was disabled on each host.”
More than a year after Warlock first appeared exploiting SharePoint flaws, researchers warn that ToolShell and other Microsoft SharePoint vulnerabilities remain important initial-access vectors.
The report from Symantec and Carbon Black threat hunters includes indicators of compromise for files and infrastructure used in the attack.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a 2-hour digital summit about what will change with AI speed attacks, what defenders should stop doing, and how to verify, decide, fix, and revalidate at machine speed.
Source: www.bleepingcomputer.com



