A China-linked ransomware operation called Warlock has broken into a water utility, a telecom provider, a regional government body and a university, using flaws in Microsoft SharePoint to get its first foothold. The group spent the past two months concentrating on Portuguese- and Spanish-speaking countries across Europe, Africa and Latin America, according to research from Symantec and Carbon Black. The findings point to an intrusion campaign that reached production networks in several sectors at once.

Warlock appeared in June 2025 and drew attention a month later by exploiting a chain of SharePoint zero-days tracked as ToolShell: CVE-2025-49704, CVE-2025-49706, CVE-2025-53770 and CVE-2025-53771. By August, Microsoft had observed the state-backed groups Linen Typhoon and Violet Typhoon using ToolShell exploits, alongside a ransomware actor Microsoft calls Storm-2603. Symantec identifies that same actor as Longlegs and credits it with developing the Warlock ransomware.

In one intrusion that began July 22, the attacker used a tool that switched off protection software on at least 40 hosts in roughly two hours, then launched Warlock ransomware on at least 33 hosts, the researchers said. Initial access typically came through vulnerabilities in on-premises SharePoint deployments, after which the attacker installed a web shell built to run across multiple SharePoint versions. In some Longlegs attacks, an antivirus and endpoint detection killer was delivered through the bring your own vulnerable driver technique, using a signed K7RKScan driver exposed to CVE-2025-1055.

Analysis of the July 22 intrusion showed the attacker conducting reconnaissance two days after gaining access and removing what appeared to be staging artifacts. The ransomware payload was placed in the domain's SYSVOL share, which holds public files and replicates to every domain controller. The researchers described this as a known way to push a payload across an entire network at once for execution by a logon script or Group Policy object rather than host by host.

The main executable for Visual Studio Code Insiders was installed as a service so the attacker could connect remotely to compromised machines through VS Code's built-in tunneling. On one system, researchers found NetExec, an open-source penetration testing framework, which supported Active Directory enumeration, credential spraying and remote command execution. The final stage came July 31, when Warlock ransomware appeared almost immediately after protection was disabled on each host.

The researchers warn that ToolShell and other SharePoint vulnerabilities remain usable initial access vectors more than a year after Warlock first emerged by exploiting SharePoint flaws. Their report includes indicators of compromise covering files and infrastructure tied to the attacks. For US defenders, the findings underscore that unpatched on-premises SharePoint servers remain a live path into enterprise and public-sector networks.

More cybersecurity news from TechManNews.