Warlock Ransomware Hits Water and Telecom via SharePoint Flaws

•By CyberNewsAI Admin•VERIFIED INTEL
Warlock Ransomware Attack Chain and SharePoint Exploitation Telemetry Overview

SOC Briefing Summary :: Executive Key Takeaways

  • [01]China-linked ransomware group Warlock (tracked as Longlegs) targeted a water utility, telecom provider, regional government, and university using SharePoint exploits.
  • [02]The intrusion chain deployed a BYOVD EDR-killer via a signed K7RKScan driver to blind 40 endpoints in two hours, utilizing VS Code Insiders services for reverse tunneling.
  • [03]Adversaries staged Warlock ransomware binaries in the Active Directory SYSVOL share, achieving automated network-wide execution via Group Policy Objects.
SHARE INTEL:Reddit

Executive Summary

The China-linked ransomware operation known as Warlock (tracked by Symantec and Carbon Black as Longlegs) has escalated its targeting against critical infrastructure, compromising a municipal water utility, a telecommunications provider, a regional government administrative body, and a university. The campaign concentrated heavily on Portuguese and Spanish-speaking organizations across Europe, Africa, and Latin America.

Warlock achieved perimeter breach by exploiting on-premises Microsoft SharePoint vulnerabilities known collectively as ToolShell (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771). After establishing persistence with universal SharePoint web shells, the threat actors demonstrated high operational speed, deploying a Bring Your Own Vulnerable Driver (BYOVD) security-killer that neutralized endpoint protection on 40 hosts within two hours.

To ensure enterprise-wide encryption, the operators staged the Warlock ransomware payload directly inside the Active Directory SYSVOL domain share. By tying execution to Group Policy Objects (GPOs), the attackers triggered near-instantaneous encryption across 33 domain endpoints the moment security defenses were silenced.

---

Technical Vulnerability Analysis & Attack Chain

Attack Chain Flow
// Attack Chain Flow

Stage 1: On-Premises SharePoint Exploitation & Web Shell Deployment

Warlock leveraged unpatched on-premises Microsoft SharePoint servers as its initial ingress vector. The threat actor weaponized the ToolShell vulnerability chain, which combines authentication bypasses and remote code execution flaws:

  • Web Shell Delivery: Upon executing arbitrary code in the context of the SharePoint application pool identity (w3wp.exe), the attackers dropped an ASPX web shell designed to operate reliably across multiple SharePoint version builds.
  • Dwell Time & Cleanup: Two days after initial infiltration, the adversaries conducted internal network reconnaissance and systematically deleted staging scripts and compiler artifacts to reduce their forensic footprint.

Stage 2 & 3: VS Code Insiders Tunneling & NetExec AD Recon

To bypass perimeter stateful inspection and outbound firewall restrictions without hosting exposed listening ports, Warlock repurposed legitimate enterprise development tools:

  • VS Code Tunnel Service: The operators installed the main executable for Visual Studio Code Insiders as a persistent background Windows service. Leveraging VS Code's native tunneling capability, the attackers routed encrypted SSH/WebSocket sessions through Microsoft-hosted relay infrastructure (*.tunnels.api.visualstudio.com), establishing an interactive, covert reverse command shell.
  • NetExec Active Directory Harvesting: Operating from the SharePoint pivot, the threat actor deployed NetExec (formerly CrackMapExec) to enumerate Domain Controllers, perform multi-account password spraying, and execute remote commands via SMB and WinRM.

Stage 4 & 5: BYOVD EDR Termination & SYSVOL GPO Blast Radius

The final execution phase combined defensive blinding with automated payload delivery:

  • BYOVD via CVE-2025-1055: The actors dropped an AV/EDR-killing utility utilizing a signed, vulnerable K7RKScan.sys driver. Because the driver carried a legitimate digital signature, Windows Driver Signature Enforcement (DSE) allowed it into kernel memory. The utility abused kernel memory write primitives to terminate security processes, unhook EDR sensors, and blind SOC telemetry across 40 endpoints in 120 minutes.
  • SYSVOL Share Staging: With administrative control secured, the operators copied the Warlock ransomware executable to the domain SYSVOL folder (\\domain\SYSVOL\Policies\...). Because SYSVOL automatically replicates across every Domain Controller in the forest, the payload became instantly available to all domain-joined workstations and servers.
  • GPO Triggered Detonation: The group deployed a Group Policy Object configured with an immediate scheduled task or logon script targeting the staged SYSVOL binary. Ransomware execution commenced across at least 33 critical hosts seconds after endpoint security agents ceased telemetry reporting.

---

MITRE ATT&CK Tactics, Techniques & Procedures (TTPs)

MITRE ATT&CK • OPERATIONAL TTP MAPPING
TacticTechnique IDTechnique NameOperational Context
Initial AccessT1190Exploit Public-Facing ApplicationWeaponizing SharePoint ToolShell vulnerabilities (CVE-2025-49704)
PersistenceT1505.003Web ShellDeploying multi-version ASPX web shells on SharePoint servers
PersistenceT1543.003Windows ServiceInstalling VS Code Insiders executable as a persistent service
Command & ControlT1572Protocol TunnelingAbusing VS Code reverse tunnels over Microsoft cloud relay infrastructure
DiscoveryT1087.002Domain Account DiscoveryPerforming Active Directory user and group enumeration via NetExec
Defense EvasionT1068 / T1562.001Impair Defenses: BYOVDExploiting signed K7RKScan driver (CVE-2025-1055) to terminate EDRs
Lateral MovementT1078.002Domain AccountsUtilizing compromised domain administrative credentials for SMB execution
ExecutionT1484.001Group Policy ModificationPropagating Warlock ransomware via domain SYSVOL shares and GPOs
ImpactT1486Data Encrypted for ImpactEncrypting enterprise data across water utility and telecom systems

---

Threat Actor Profile & Campaign Attribution

Warlock first surfaced in June 2025 and is identified by Symantec as Longlegs. Security researchers note substantial tactical clustering and exploit sharing with Chinese state-sponsored espionage groups:

  • Shared ToolShell Weaponization: In late summer 2025, Microsoft observed Chinese state-backed groups Linen Typhoon and Violet Typhoon deploying ToolShell exploits in parallel with a ransomware threat group designated Storm-2603.
  • Dual Motivation: The focus on municipal water utilities, telecommunication networks, and regional government ministries in Latin America, Europe, and Africa highlights hybrid objectives—combining destructive financial extortion with strategic critical infrastructure disruption.

---

Detection & SOC Mitigation Playbook

1. Patch & Workaround Guidance

  • Patch SharePoint On-Premises: Apply cumulative security updates addressing CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771 across all SharePoint Foundation and Enterprise server farms.
  • Enforce Driver Blocklists: Enable Hypervisor-Protected Code Integrity (HVCI) and implement the Microsoft Recommended Driver Block Rules to prevent the loading of known vulnerable drivers, specifically K7RKScan.sys.
  • Lock Down SYSVOL Permissions: Restrict write permissions on the SYSVOL and Netlogon shares to Domain Admins and audit file creation events for executable (.exe, .dll, .bat, .ps1) file extensions.

2. Network & Perimeter Defenses

  • Block VS Code Tunnel Relays: Inspect egress proxy logs and block outbound connections to *.tunnels.api.visualstudio.com and related Azure relay domains on servers not explicitly designated for remote engineering.
  • Isolate SharePoint Farms: Place SharePoint servers in segmented DMZ subnets with restricted egress to the Active Directory domain and zero direct access to critical database tiers.

3. Endpoint Detection & Hunting Query

Sigma Rule: Malicious Driver Loading and VS Code Service Creation

QUERY / DETECTION_RULE
SIGMA / YAML
title: Warlock Ransomware BYOVD Driver or VS Code Tunnel Service
id: c72e4b11-9821-4f12-98ba-d5798a12e105
status: experimental
description: Detects execution of signed K7RKScan driver or installation of VS Code Insiders as a persistent Windows service.
references:
  - https://www.bleepingcomputer.com/news/security/warlock-ransomware-breach-sharepoint-in-water-telecom-operator-attacks/
author: CyberNewsAI Threat Research Team
date: 2026-10-02
tags:
  - attack.defense_evasion
  - attack.t1562.001
  - attack.t1572
logsource:
  category: process_creation
  product: windows
detection:
  selection_driver:
    Image|contains: 'k7rkscan'
  selection_vscode:
    Image|endswith:
      - '\code - insiders.exe'
      - '\code-insiders.exe'
    CommandLine|contains:
      - 'tunnel'
      - 'service install'
  condition: selection_driver or selection_vscode
falsepositives:
  - Legitimate developer use of VS Code remote tunnels on developer workstations (abnormal on SharePoint servers or DCs).
level: critical

Microsoft Sentinel / Defender KQL Hunting Query

QUERY / DETECTION_RULE
SENTINEL / KQL
// Hunt for VS Code Tunnel service creation, NetExec AD activity, or BYOVD driver load
DeviceProcessEvents
| where Timestamp > ago(7d)
| where (FileName in~ ("code-insiders.exe", "code.exe") and ProcessCommandLine has "tunnel")
    or (ProcessCommandLine has_any ("netexec", "crackmapexec", "K7RKScan.sys"))
    or (FolderPath has @"\SYSVOL\" and FileName endswith ".exe")
| project Timestamp, DeviceName, ActionType, FileName, FolderPath, ProcessCommandLine, InitiatingProcessFileName, AccountName
| order by Timestamp desc

---

Indicator TypeValue / PatternContext
Threat GroupWarlock / LonglegsChina-linked ransomware operation targeting utilities
Initial Access CVEsCVE-2025-49704, CVE-2025-49706, CVE-2025-53770, CVE-2025-53771SharePoint ToolShell vulnerability chain
BYOVD DriverK7RKScan.sys (CVE-2025-1055)Signed driver abused to disable EDR/AV on 40 endpoints
Tunneling BinaryCode - Insiders.exeVisual Studio Code binary abused as tunnel service
Post-Exploitation ToolNetExecOpen-source Active Directory exploitation framework
Staging Path\\<Domain>\SYSVOL\<Domain>\Policies\...Staging location for domain-wide GPO ransomware detonation
Indicators of Compromise (IOCs)
6 Identified
Threat ActorWarlock / Longlegs (China-linked)
Vulnerability ChainToolShell (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, CVE-2025-53771)
BYOVD Vulnerable DriverK7RKScan.sys (CVE-2025-1055)
Tunneling MechanismVisual Studio Code Insiders Tunnel Service
Post-Exploitation ToolNetExec (Active Directory enumeration & spraying)
Propagation VectorActive Directory SYSVOL Share & Group Policy Objects
// EVERGREEN RELIC // P1 INCIDENT
Friday 4:59 PM // The SOC Raccoon Heavyweight Tee - Light mockup

Friday 4:59 PM // The SOC Raccoon Heavyweight Tee - Light

“Because nation-state APTs strictly observe your weekend plans.”

Commemorate this cyber event. Printed on ultra-comfortable vintage garment-dyed 100% ring-spun cotton. Engineered for SOC war rooms, late-night incident bridges, and DEFCON.

Direct Armory Fulfillment$20
ACQUIRE RELIC
Fast US Shipping (2-4 Days)• 1-Click Apple / Google Pay
SHARE INTEL:Reddit
OPERATIONS_BROADCAST

Watch Full Video Briefings on YouTube

Subscribe to CyberNewsAI on YouTube for animated threat vectors, CISO breakdowns, and security briefings.

SUBSCRIBE_ON_YOUTUBE