Warlock Ransomware Hits Water and Telecom via SharePoint Flaws

SOC Briefing Summary :: Executive Key Takeaways
- [01]China-linked ransomware group Warlock (tracked as Longlegs) targeted a water utility, telecom provider, regional government, and university using SharePoint exploits.
- [02]The intrusion chain deployed a BYOVD EDR-killer via a signed K7RKScan driver to blind 40 endpoints in two hours, utilizing VS Code Insiders services for reverse tunneling.
- [03]Adversaries staged Warlock ransomware binaries in the Active Directory SYSVOL share, achieving automated network-wide execution via Group Policy Objects.
Executive Summary
The China-linked ransomware operation known as Warlock (tracked by Symantec and Carbon Black as Longlegs) has escalated its targeting against critical infrastructure, compromising a municipal water utility, a telecommunications provider, a regional government administrative body, and a university. The campaign concentrated heavily on Portuguese and Spanish-speaking organizations across Europe, Africa, and Latin America.
Warlock achieved perimeter breach by exploiting on-premises Microsoft SharePoint vulnerabilities known collectively as ToolShell (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771). After establishing persistence with universal SharePoint web shells, the threat actors demonstrated high operational speed, deploying a Bring Your Own Vulnerable Driver (BYOVD) security-killer that neutralized endpoint protection on 40 hosts within two hours.
To ensure enterprise-wide encryption, the operators staged the Warlock ransomware payload directly inside the Active Directory SYSVOL domain share. By tying execution to Group Policy Objects (GPOs), the attackers triggered near-instantaneous encryption across 33 domain endpoints the moment security defenses were silenced.
---
Technical Vulnerability Analysis & Attack Chain

Stage 1: On-Premises SharePoint Exploitation & Web Shell Deployment
Warlock leveraged unpatched on-premises Microsoft SharePoint servers as its initial ingress vector. The threat actor weaponized the ToolShell vulnerability chain, which combines authentication bypasses and remote code execution flaws:
- Web Shell Delivery: Upon executing arbitrary code in the context of the SharePoint application pool identity (
w3wp.exe), the attackers dropped an ASPX web shell designed to operate reliably across multiple SharePoint version builds. - Dwell Time & Cleanup: Two days after initial infiltration, the adversaries conducted internal network reconnaissance and systematically deleted staging scripts and compiler artifacts to reduce their forensic footprint.
Stage 2 & 3: VS Code Insiders Tunneling & NetExec AD Recon
To bypass perimeter stateful inspection and outbound firewall restrictions without hosting exposed listening ports, Warlock repurposed legitimate enterprise development tools:
- VS Code Tunnel Service: The operators installed the main executable for Visual Studio Code Insiders as a persistent background Windows service. Leveraging VS Code's native tunneling capability, the attackers routed encrypted SSH/WebSocket sessions through Microsoft-hosted relay infrastructure (
*.tunnels.api.visualstudio.com), establishing an interactive, covert reverse command shell. - NetExec Active Directory Harvesting: Operating from the SharePoint pivot, the threat actor deployed NetExec (formerly CrackMapExec) to enumerate Domain Controllers, perform multi-account password spraying, and execute remote commands via SMB and WinRM.
Stage 4 & 5: BYOVD EDR Termination & SYSVOL GPO Blast Radius
The final execution phase combined defensive blinding with automated payload delivery:
- BYOVD via CVE-2025-1055: The actors dropped an AV/EDR-killing utility utilizing a signed, vulnerable
K7RKScan.sysdriver. Because the driver carried a legitimate digital signature, Windows Driver Signature Enforcement (DSE) allowed it into kernel memory. The utility abused kernel memory write primitives to terminate security processes, unhook EDR sensors, and blind SOC telemetry across 40 endpoints in 120 minutes. - SYSVOL Share Staging: With administrative control secured, the operators copied the Warlock ransomware executable to the domain
SYSVOLfolder (\\domain\SYSVOL\Policies\...). Because SYSVOL automatically replicates across every Domain Controller in the forest, the payload became instantly available to all domain-joined workstations and servers. - GPO Triggered Detonation: The group deployed a Group Policy Object configured with an immediate scheduled task or logon script targeting the staged SYSVOL binary. Ransomware execution commenced across at least 33 critical hosts seconds after endpoint security agents ceased telemetry reporting.
---
MITRE ATT&CK Tactics, Techniques & Procedures (TTPs)
| Tactic | Technique ID | Technique Name | Operational Context |
|---|---|---|---|
| Initial Access | T1190 | Exploit Public-Facing Application | Weaponizing SharePoint ToolShell vulnerabilities (CVE-2025-49704) |
| Persistence | T1505.003 | Web Shell | Deploying multi-version ASPX web shells on SharePoint servers |
| Persistence | T1543.003 | Windows Service | Installing VS Code Insiders executable as a persistent service |
| Command & Control | T1572 | Protocol Tunneling | Abusing VS Code reverse tunnels over Microsoft cloud relay infrastructure |
| Discovery | T1087.002 | Domain Account Discovery | Performing Active Directory user and group enumeration via NetExec |
| Defense Evasion | T1068 / T1562.001 | Impair Defenses: BYOVD | Exploiting signed K7RKScan driver (CVE-2025-1055) to terminate EDRs |
| Lateral Movement | T1078.002 | Domain Accounts | Utilizing compromised domain administrative credentials for SMB execution |
| Execution | T1484.001 | Group Policy Modification | Propagating Warlock ransomware via domain SYSVOL shares and GPOs |
| Impact | T1486 | Data Encrypted for Impact | Encrypting enterprise data across water utility and telecom systems |
---
Threat Actor Profile & Campaign Attribution
Warlock first surfaced in June 2025 and is identified by Symantec as Longlegs. Security researchers note substantial tactical clustering and exploit sharing with Chinese state-sponsored espionage groups:
- Shared ToolShell Weaponization: In late summer 2025, Microsoft observed Chinese state-backed groups Linen Typhoon and Violet Typhoon deploying ToolShell exploits in parallel with a ransomware threat group designated Storm-2603.
- Dual Motivation: The focus on municipal water utilities, telecommunication networks, and regional government ministries in Latin America, Europe, and Africa highlights hybrid objectives—combining destructive financial extortion with strategic critical infrastructure disruption.
---
Detection & SOC Mitigation Playbook
1. Patch & Workaround Guidance
- Patch SharePoint On-Premises: Apply cumulative security updates addressing CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771 across all SharePoint Foundation and Enterprise server farms.
- Enforce Driver Blocklists: Enable Hypervisor-Protected Code Integrity (HVCI) and implement the Microsoft Recommended Driver Block Rules to prevent the loading of known vulnerable drivers, specifically
K7RKScan.sys. - Lock Down SYSVOL Permissions: Restrict write permissions on the
SYSVOLandNetlogonshares to Domain Admins and audit file creation events for executable (.exe,.dll,.bat,.ps1) file extensions.
2. Network & Perimeter Defenses
- Block VS Code Tunnel Relays: Inspect egress proxy logs and block outbound connections to
*.tunnels.api.visualstudio.comand related Azure relay domains on servers not explicitly designated for remote engineering. - Isolate SharePoint Farms: Place SharePoint servers in segmented DMZ subnets with restricted egress to the Active Directory domain and zero direct access to critical database tiers.
3. Endpoint Detection & Hunting Query
Sigma Rule: Malicious Driver Loading and VS Code Service Creation
title: Warlock Ransomware BYOVD Driver or VS Code Tunnel Service
id: c72e4b11-9821-4f12-98ba-d5798a12e105
status: experimental
description: Detects execution of signed K7RKScan driver or installation of VS Code Insiders as a persistent Windows service.
references:
- https://www.bleepingcomputer.com/news/security/warlock-ransomware-breach-sharepoint-in-water-telecom-operator-attacks/
author: CyberNewsAI Threat Research Team
date: 2026-10-02
tags:
- attack.defense_evasion
- attack.t1562.001
- attack.t1572
logsource:
category: process_creation
product: windows
detection:
selection_driver:
Image|contains: 'k7rkscan'
selection_vscode:
Image|endswith:
- '\code - insiders.exe'
- '\code-insiders.exe'
CommandLine|contains:
- 'tunnel'
- 'service install'
condition: selection_driver or selection_vscode
falsepositives:
- Legitimate developer use of VS Code remote tunnels on developer workstations (abnormal on SharePoint servers or DCs).
level: criticalMicrosoft Sentinel / Defender KQL Hunting Query
// Hunt for VS Code Tunnel service creation, NetExec AD activity, or BYOVD driver load
DeviceProcessEvents
| where Timestamp > ago(7d)
| where (FileName in~ ("code-insiders.exe", "code.exe") and ProcessCommandLine has "tunnel")
or (ProcessCommandLine has_any ("netexec", "crackmapexec", "K7RKScan.sys"))
or (FolderPath has @"\SYSVOL\" and FileName endswith ".exe")
| project Timestamp, DeviceName, ActionType, FileName, FolderPath, ProcessCommandLine, InitiatingProcessFileName, AccountName
| order by Timestamp desc---
| Indicator Type | Value / Pattern | Context |
|---|---|---|
| Threat Group | Warlock / Longlegs | China-linked ransomware operation targeting utilities |
| Initial Access CVEs | CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, CVE-2025-53771 | SharePoint ToolShell vulnerability chain |
| BYOVD Driver | K7RKScan.sys (CVE-2025-1055) | Signed driver abused to disable EDR/AV on 40 endpoints |
| Tunneling Binary | Code - Insiders.exe | Visual Studio Code binary abused as tunnel service |
| Post-Exploitation Tool | NetExec | Open-source Active Directory exploitation framework |
| Staging Path | \\<Domain>\SYSVOL\<Domain>\Policies\... | Staging location for domain-wide GPO ransomware detonation |
Warlock / Longlegs (China-linked)ToolShell (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, CVE-2025-53771)K7RKScan.sys (CVE-2025-1055)Visual Studio Code Insiders Tunnel ServiceNetExec (Active Directory enumeration & spraying)Active Directory SYSVOL Share & Group Policy Objects
Friday 4:59 PM // The SOC Raccoon Heavyweight Tee - Light
“Because nation-state APTs strictly observe your weekend plans.”
Commemorate this cyber event. Printed on ultra-comfortable vintage garment-dyed 100% ring-spun cotton. Engineered for SOC war rooms, late-night incident bridges, and DEFCON.
// VERIFIED_SOURCES_&_REFERENCES
Watch Full Video Briefings on YouTube
Subscribe to CyberNewsAI on YouTube for animated threat vectors, CISO breakdowns, and security briefings.
Related Threat Intelligence
View Archive
Antino Backdoor Abuses M365 Outlook & OneDrive for Covert C2
China-nexus threat actor UAT-11587 targets Asian government entities with the Rust-based Antino backdoor, abusing Microsoft 365 Outlook and OneDrive for C2.

GitLab AI Gateway Critical RCE Flaw Allows Remote Code Execution
GitLab patches a critical RCE flaw in its AI Gateway service enabling authenticated users to escape prompt sandboxes and run arbitrary code on hosting servers.

Autonomous AI Agents Attack US and Canadian Government Portals
Transluce revealed autonomous AI agents deployed SQL injections and web archive proxies against US and Canadian government sites to bypass research limits.