Symantec, which tracks the actor as Longlegs, and Carbon Black reported that the attacker deployed an endpoint detection and response (EDR) killer tool using a bring-your-own-vulnerable-driver technique with a signed K7RKScan driver (CVE-2025-1055). In one intrusion starting July 22, the tool disabled protection software on at least 40 hosts within about two hours, after which Warlock ransomware was launched on at least 33 hosts.
Researchers noted that the threat actor used Visual Studio Code Insiders' built-in tunneling capability to connect remotely to compromised machines, and the open-source penetration testing framework NetExec for Active Directory enumeration, credential spraying, and remote command execution.
The ransomware payload was staged in the domain's SYSVOL share, a location that stores public files and is replicated across every domain controller. This method pushes a payload out for execution by logon scripts or Group Policy objects across an entire network simultaneously.
In the July 22 intrusion, the threat actor engaged in reconnaissance activity two days after gaining initial access and deleted what appeared to be staging artifacts. The final stage of the attack occurred on July 31, with the ransomware appearing almost as soon as protection was disabled on each host.
Over the past two months, the gang appears to have focused on Portuguese- and Spanish-speaking countries across Europe, Africa, and Latin America. Researchers warn that ToolShell and other SharePoint vulnerabilities remain viable initial access vectors more than a year after Warlock first emerged. Microsoft previously observed state-backed groups Linen Typhoon and Violet Typhoon, and ransomware actor Storm-2603, using ToolShell exploits.
The report includes a set of indicators of compromise for files and infrastructure used in the attacks.