Warlock Ransomware Uses SharePoint Flaws to Hit Utilities & Telecom

A threat actor linked to China is actively exploiting vulnerabilities in Microsoft SharePoint servers to deploy Warlock ransomware, with recent attacks targeting critical infrastructure in Portuguese- and Spanish-speaking countries. At least four organizations—a water utility, telecom provider, regional government, and university—across Europe, Latin America and Africa have been hit during the past two months.

How the SharePoint Exploits Work

First discovered in June 2025, Warlock emerged through a SharePoint exploit chain called “ToolShell,” which combined newly identified flaws CVE-2025-49704 and CVE-2025-49706. Subsequent bypasses, CVE-2025-53770 and CVE-2025-53771, kept the attacker’s access methods up to date.

Once inside, the attacker—tracked as Longlegs by Symantec (Storm-2603 by Microsoft)—plants an ASPX webshell into the SharePoint LAYOUTS directory. This webshell pulls ASP.NET machine keys, enabling forged __VIEWSTATE payloads and arbitrary code execution in the application pool.

From Initial Access to Ransomware Chaos

Following compromise, the campaign uses DLL sideloading and leverages legitimate hosting services like Catbox and Wasabi to disguise malicious activity as ordinary cloud traffic. One attack starting on July 22, 2026, saw Longlegs run domain-enumeration commands, deploy sideloading pairs, and abuse Visual Studio Code’s tunnel feature for stealthy access.

To disable defenses, the actor pushes tools to kill antivirus and endpoint detection (EDR) across many hosts in a short span. They also use a signed yet vulnerable driver (CVE-2025-1055) to terminate privileged processes from kernel space, exploiting missing authorization in the driver’s IOCTL handler.

For spreading the ransomware, the attacker places executables and ransom notes into the SYSVOL share of Active Directory domains. Because SYSVOL replicates across domain controllers and is readable throughout the domain, this method lets the attacker distribute the ransomware widely via trusted replication mechanisms.

Mitigations & What Organizations Should Do Now

While patching the SharePoint vulnerabilities is crucial, it’s not enough alone. Organizations should hunt for indicators like webshells, abnormal SharePoint worker-process behavior, and requests to ToolPane.aspx. After cleaning, they should rotate machine keys for ASP.NET and IIS, enable AMSI in full mode, make use of EDR tools, and limit SharePoint’s exposure to the internet.

Further protective steps include placing public-facing SharePoint behind authenticated Layer-7 proxies, blocking external access to Central Administration, and having robust asset discovery and recovery planning—especially in sectors like water, telecom, government, and education where delays in remediation can lead to domain-wide operational disruption.

This campaign underscores how SharePoint vulnerabilities remain a potent vector for ransomware actors. The fact that SYSVOL replication is exploited for ransomware spread is especially alarming. Monitoring for suspicious activity, rapid patching, and defensive depth are non-negotiable. With Longlegs’ evolving methods, defenders must assume exposure until proven otherwise—this isn’t just about fixing holes; it’s about overhauling assumptions about what’s trusted infrastructure.