China-linked Warlock ransomware targets water utility and telecoms via SharePoint flaws

Symantec and Carbon Black report attacks exploiting unpatched vulnerabilities continue more than a year after group emerged

By LineZotpaper
Published
Read Time2 min
The China-linked ransomware group Warlock has breached a water utility, a telecommunications provider, a regional government body, and a university by exploiting a chain of Microsoft SharePoint vulnerabilities, according to cybersecurity researchers from Symantec and Carbon Black. The group, which emerged in June 2025, used a known zero-day exploit chain called ToolShell (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, CVE-2025-53771) to gain initial access to on-premises SharePoint deployments.

Symantec, which tracks the actor as Longlegs, and Carbon Black reported that the attacker deployed an endpoint detection and response (EDR) killer tool using a bring-your-own-vulnerable-driver technique with a signed K7RKScan driver (CVE-2025-1055). In one intrusion starting July 22, the tool disabled protection software on at least 40 hosts within about two hours, after which Warlock ransomware was launched on at least 33 hosts.

Researchers noted that the threat actor used Visual Studio Code Insiders' built-in tunneling capability to connect remotely to compromised machines, and the open-source penetration testing framework NetExec for Active Directory enumeration, credential spraying, and remote command execution.

The ransomware payload was staged in the domain's SYSVOL share, a location that stores public files and is replicated across every domain controller. This method pushes a payload out for execution by logon scripts or Group Policy objects across an entire network simultaneously.

In the July 22 intrusion, the threat actor engaged in reconnaissance activity two days after gaining initial access and deleted what appeared to be staging artifacts. The final stage of the attack occurred on July 31, with the ransomware appearing almost as soon as protection was disabled on each host.

Over the past two months, the gang appears to have focused on Portuguese- and Spanish-speaking countries across Europe, Africa, and Latin America. Researchers warn that ToolShell and other SharePoint vulnerabilities remain viable initial access vectors more than a year after Warlock first emerged. Microsoft previously observed state-backed groups Linen Typhoon and Violet Typhoon, and ransomware actor Storm-2603, using ToolShell exploits.

The report includes a set of indicators of compromise for files and infrastructure used in the attacks.

§

Analysis

Why This Matters

  • Critical infrastructure sectors – water, telecom, government – face ongoing ransomware threats that can disrupt essential services
  • Reliance on Microsoft SharePoint remains a vulnerability point; unpatched flaws continue to be exploited months after disclosure
  • The use of BYOVD (bring your own vulnerable driver) techniques to disable security software poses a persistent challenge for defenders

Background

Warlock ransomware first appeared in June 2025 and gained notoriety in July when it exploited a chain of zero-day vulnerabilities in Microsoft SharePoint collectively called ToolShell. The vulnerabilities include CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771. By August 2025, Microsoft had observed state-backed hacking groups and ransomware actors using the same exploits. Symantec tracks the group behind Warlock as Longlegs, while Microsoft calls it Storm-2603. The group primarily targets on-premises SharePoint deployments.

Key Perspectives

Victim organizations: Water utilities, telecom providers, governments and universities face operational disruptions, data loss and extortion demands, with limited recourse if patching is delayed. Security researchers (Symantec/Carbon Black): Highlight that the threat actor remains active and continues to find success with older exploits, urging organisations to patch SharePoint vulnerabilities and monitor for EDR-killing tools. Microsoft and affected vendors: Have released patches for the ToolShare exploit chain, but unpatched systems remain at risk. The persistence of BYOVD techniques suggests driver signing controls need stronger enforcement.

What to Watch

  • Indicators of compromise from Symantec/Carbon Black report to help defenders detect infections
  • Whether organisations in Portuguese- and Spanish-speaking regions accelerate patching of SharePoint
  • Emergence of new variants of Warlock or copycat groups using similar initial access methods

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.