Warlock Ransomware Exploiting SharePoint Flaws to Attack Water and Telecom Operators

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


A China-nexus threat actor is continuing to exploit Microsoft SharePoint Server vulnerabilities to deploy Warlock ransomware, with recent attacks striking essential-service and public-sector organizations across Portuguese- and Spanish-speaking countries.

Symantec tracks the operator as Longlegs, while Microsoft uses Storm-2603; earlier activity has also been linked to CL-CRI-1040, CamoFei, and ChamelGang.

During the past two months, the campaign compromised at least four organizations: a water utility, a telecommunications provider, a regional government body, and a university spanning Europe, Africa, and Latin America.

Warlock Ransomware Exploiting SharePoint Flaws

Warlock surfaced in June 2025 and quickly gained attention after being deployed through the SharePoint “ToolShell” exploit chain. ToolShell combined CVE-2025-49704 and CVE-2025-49706, while subsequent bypasses were assigned CVE-2025-53770 and CVE-2025-53771.

CISA confirmed that the chain enabled unauthorized access to on-premises SharePoint servers, exposure of internal configurations, and remote code execution.

Warlock was among the ransomware payloads observed on compromised systems. Newer SharePoint flaws disclosed in 2026 have kept the attack surface relevant, with CISA warning of active exploitation affecting supported on-premises editions.

According to research published by Symantec, Longlegs typically plants an ASPX webshell in SharePoint’s LAYOUTS directory, targeting several product versions simultaneously.

The webshell extracts ASP.NET machine keys, allowing the attackers to forge signed __VIEWSTATE payloads and execute code inside the SharePoint application pool.

Follow-on malware is then loaded through DLL sideloading, while installers are retrieved from legitimate hosting services, including Catbox and Wasabi, helping malicious traffic resemble routine cloud activity.

In one critical-infrastructure intrusion, activity began on July 22, 2026, when a webshell appeared on a SharePoint server. The attackers later ran whoami, net user /domain, and nltest /domain_trusts, deployed sideloading pairs, and used NetExec for Active Directory discovery, credential spraying, and remote execution.

They also installed Microsoft-signed code-insiders.exe as a service and abused Visual Studio Code’s tunnel function, creating covert access through infrastructure that defenders may associate with legitimate administrators or developers.

Before encryption, Longlegs pushed an AV and EDR termination utility to at least 40 hosts in roughly two hours. Recent operations have used the signed but vulnerable K7RKScan driver, tracked as CVE-2025-1055, to terminate privileged processes from kernel space a bring-your-own-vulnerable-driver technique.

NIST says the flaw stems from missing authorization in the driver’s IOCTL handler and affects K7 Security Anti-Malware versions earlier than 23.0.0.10. Investigators cautioned that they did not conclusively identify the specific driver used in this intrusion.

Warlock followed almost immediately on at least 33 systems. The attackers placed run.exe, rune.exe, and the ransom note “how to restore your files.txt” in the compromised domain’s SYSVOL share.

Because SYSVOL replicates across domain controllers and is readable domain-wide, ordinary Distributed File System Replication helped deliver the payload broadly, turning trusted Active Directory infrastructure into a ransomware distribution channel.

The campaign shows why patching alone is insufficient after suspected SharePoint exploitation. Defenders should hunt for webshells and abnormal SharePoint worker-process behavior, rotate ASP.NET and IIS machine keys after removing persistence, enable AMSI in Full Mode, deploy EDR, restrict SharePoint’s internet exposure, and inspect suspicious ToolPane.aspx requests.

CISA additionally recommends placing any necessary public-facing deployment behind an authenticated Layer 7 proxy and blocking external access to Central Administration. For water, telecom, government, and education operators, delayed remediation can transform one exposed collaboration server into domain-wide operational disruption.

The targeting pattern may reflect vulnerable exposed servers or deliberate regional tasking, but either explanation demands urgent asset discovery, containment, and recovery planning now.

File Indicators

SHA-256 Hash Classification
116ca4e88a1bcebb6c0da7fb431c8eca7b8ef3f9767194820c56091972ccac2c Warlock ransomware
155fb1cbdaea12c83ba92d18c88cf38bbc42bb684f913ca0bc26fcf115426a55 Warlock ransomware
1edb2c0b537cd95bbd5fc16321b4c38a6adf325ccc7b588ad6acc980b0463b60 Malicious DLL
206f27ae820783b7755bca89f83a0fe096dbb510018dd65b63fc80bd20c03261 Malicious DLL
27b7591cf9e1283010ca98fa5dbe970a73fee0d8cde277639924c144718db7c0 Malicious DLL
37f94fe1b4a106f02b6f74a69cbc05e69c17406f688beef4c9a045ffcbd2e65e Suspicious file
6d07f1232dc59b84038fd0b2e75fdd3d5b825882bb0dba9e6724b7b0823fa3ad Warlock ransomware
73c5268256c9da5488cd9e2b79013060ac321c7e54129344dc7b51e268af36ea AV/EDR killer
8b58f7811a2a2f2a5024220490473774f02759dd2dd904b5b9fabfbaae37125f Warlock ransomware
8ce8d8270ee9de02644530b8dd7fa78973b4a3b80f121e2c5f45ae68cce196f9 Warlock ransomware
9ceb01f8bf7d6dba2ae07f5bd6070de3ec67b5eb01f969b0ba85e74564fb83a7 Suspicious file
aaff04d84ef85353966aa4af186ff1254b72c068f33f802417b29dc23fb9f192 Suspicious file
ae9f7fce57c7b928e659dccf0e00fa79cd9cd61a106f18d4e03f92dc3a03c295 Vulnerable driver
c46825fcc0d1bf7a8b192facb176d6bf916c9dccfd6fa994be691e3b0e585f4e Malicious DLL
e14240bac8277b0f6dd4d29ab5da20d246bcccae647e5fe8d19cdae7fe471b20 Malicious DLL
e3204b05e2f3a29bb6e6fcc21dda77d7cd31dfa755c21da0aa8661b5619ee0a1 Suspicious file
eea631b5f7125239db0811e4682c2316ead69f9822e02d94fb5d8bf0d2faebed Suspicious file
f7269f80f81e99d06a590d7ab374e12fdf7e5f55a02c2a46c342d670f8519fdf Suspicious file
fb3846c9ac53d1b841ada3a6b1091153fea41a169cb44fe0084097d1f4d45984 Malicious DLL

Network Indicators

Network IoC Type Observed Role
litter[.]catbox[.]moe Defanged hostname Payload-hosting and malware-delivery infrastructure
xn8xyt-drop[.]s3[.]wasabisys[.]com Defanged hostname Cloud-storage endpoint used to retrieve a malicious MSI package

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup into your SOC

The post Warlock Ransomware Exploiting SharePoint Flaws to Attack Water and Telecom Operators appeared first on Cyber Security News.