DEV Community

Anoymask
Anoymask

Posted on

Warlock: Ransomware Deployment from SYSVOL After SharePoint Compromise

1. Basic Information

  • Original Title: Warlock Ransomware Attackers Hit Water and Telecom Operators
  • Sources: Symantec and Carbon Black
  • Published: October 1, 2026
  • Updated: None
  • Severity: Critical
  • Severity Basis: Attacks were reported against at least four organizations, including water and telecommunications operators. In the detailed intrusion at a critical infrastructure organization, the execution of an AV/EDR Killer was recorded on at least 40 machines within roughly two hours, followed by the Warlock binary and ransom note on at least 33 machines. These figures do not represent the total number of enterprise-wide encrypted machines.
  • Original Article: Warlock Ransomware Attackers Hit Water and Telecom Operators
  • Related Sources: Dark Reading, Microsoft Learn: SYSVOL replication, MITRE ATT&CK: IDE Tunneling, MITRE ATT&CK: DLL
  • Related Malware: Warlock ransomware
  • Related Threat Actors: Longlegs, Storm-2603, CL-CRI-1040, CamoFei, ChamelGang
  • Related CVEs: CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, CVE-2025-53771
  • Related Products: Microsoft SharePoint Server, Microsoft Active Directory, Visual Studio Code, K7RKScan

2. Quick Summary

Longlegs (Storm-2603), assessed by Symantec as having links to China, utilized DLL sideloading, Visual Studio Code tunnels, and AV/EDR Killers following an intrusion suspected to involve SharePoint vulnerability exploitation. Warlock binaries were placed in SYSVOL, leveraging domain controller replication and host-side copying and execution for distribution. SYSVOL replication alone does not guarantee execution and encryption on all endpoints.

3. Attack Flow

Flow 1: SharePoint Breach to Warlock Deployment Observed at a Critical Infrastructure Organization

  1. Attackers gain initial access, likely by exploiting a SharePoint vulnerability, and deploy an ASPX webshell.
  2. They gather domain information using commands such as net user /domain, whoami, and nltest /domain_trusts, then deploy a DLL sideloading pair and remote access tools.
  3. An AV/EDR Killer is copied to and executed on multiple hosts. Use of a vulnerable driver in the detailed intrusion is suspected, but the driver has not been identified. K7RKScan abuse was reported in other recent attacks by the same group.
  4. Warlock is placed in the SYSVOL scripts directory, leveraging DFS Replication between domain controllers (DCs) for distribution. Payload placement via dfsrs.exe was recorded on three other machines.
  5. Attacker commands copy run.exe and rune.exe from SYSVOL to individual hosts and launch them. Replication and execution are separate operations. Both binaries and a ransom note were recorded on at least 33 hosts, but the public report does not establish that encryption completed on every one of those hosts. The mechanism used to launch the commands on each host also remains unclear.

4. Attacker Position and Execution Location

  • Initial access is reported to have likely stemmed from SharePoint vulnerability exploitation. This vector requires network reachability to the target SharePoint server, though the specific CVE exploited in recent intrusions remains unconfirmed.
  • Following code execution on SharePoint, the activity expanded within the Windows domain, resulting in payload writes to SYSVOL. Write permissions to SYSVOL and modification rights within the Active Directory directory are distinct.

5. Victim and Administrator Visibility

Victims

  • Public documentation records a ransom note named how to restore your files.txt. Specific observed scopes for file extension changes or shared resource downtime are not detailed.
  • Inference: If encryption is successfully completed, symptoms such as inaccessible files and unavailable shared resources may appear.

Administrators

  • Indicators include malicious ASPX files on SharePoint, command execution originating from IIS worker processes, DLL sideloading files, service registrations involving code-insiders.exe, AV/EDR Killers, and payloads within SYSVOL. Verify file replication between DCs by dfsrs.exe and payload execution on individual hosts using separate evidence.

6. Conditions for Success and Failure

Success Conditions

  • Attackers successfully access unpatched or exploitable SharePoint instances and execute code via webshells or similar means.
  • Attackers possess write permissions to SYSVOL alongside the privileges and pathways required to execute payloads on target hosts. Specific methods for privilege acquisition remain unconfirmed.
  • Payload execution must not be blocked on the target host, and the executing process must have write access to the files targeted for encryption. Disabling security controls can facilitate the attack, but successful use of an AV/EDR Killer or a particular driver is not necessarily required for ransomware execution.

Failure Conditions

  • Patch SharePoint, restrict external exposure, and monitor for webshell activity.
  • Use application control and vulnerable driver blocklists to block EDR Killers and unauthorized binaries.
  • Restrict write access to the SYSVOL scripts directory and monitor changes in real time.
  • Verify offline or immutable backups and test Active Directory recovery procedures.

7. What Happens Upon Success

  • In the detailed intrusion, the Warlock binary and ransom note were recorded on at least 33 machines. The number of successfully encrypted machines has not been publicly disclosed.
  • The same intrusion recorded AV/EDR Killer execution on at least 40 machines within approximately two hours. This is distinct from individually confirmed instances of completed defense neutralization on each host.
  • Inference: While successful encryption leads to operational disruption and recovery overhead, the specific service outage scope for affected organizations such as water and telecommunications operators cannot be determined from public disclosures.

8. Observable Logs

Email

  • Not a direct vector for this campaign. Phishing alerts should not be treated as primary evidence.

Proxy / SWG / DNS

  • Monitor for requests exploiting SharePoint, access to webshells, and traffic communicating with litter[.]catbox[.]moe, Wasabi S3 domains, and Visual Studio Code tunneling services.

Endpoint / EDR

  • Review for PowerShell or cmd execution spawned under w3wp.exe, creation of ASPX files, DLL sideloading, driver loading, termination of security processes, execution of run.exe or rune.exe, and the presence of ransom notes.

Identity / IdP

  • Check for domain account usage, modifications to privileged groups, service account activity, lateral movement sessions, and entities writing to SYSVOL.

SaaS / Cloud

  • Review usage of Visual Studio Code tunnel accounts and services, as well as access to external storage repositories.

Network

  • Monitor connections originating from SharePoint to domain controllers or numerous hosts, Visual Studio Code tunneling traffic, outbound downloads, and domain-wide SMB access.

9. Attack Success Assessment

Confirm Initial Execution

  • Public Information and Criteria: Public disclosures indicate webshell placement on SharePoint and subsequent command execution during the detailed intrusion. The initial access CVE remains unconfirmed. Criteria: Separate file placement from code execution; confirm execution through indicators such as attacker commands originating from IIS worker processes or malicious DLL loading. The mere presence of files or exploitation requests does not confirm execution success or exploitation of a specific CVE.
  • Scope: SharePoint Server
  • Related CVEs: Unconfirmed (the four listed CVEs relate to historical ToolShell activity)

Confirm Subsequent Compromise

  • Public Information and Criteria: Public reports note AV/EDR Killers, Visual Studio Code tunnel service registration, and Warlock distribution via SYSVOL. Criteria: Document unauthorized remote connections, defense termination, placement in SYSVOL, DC replication, and distribution to individual hosts using distinct evidence. The presence of a tunnel or driver on a single machine does not constitute confirmed domain-wide deployment success.
  • Scope: Windows Domain / Active Directory
  • Related CVEs: None

Confirm Subsequent Compromise

  • Public Information and Criteria: Public records indicate Warlock binaries and ransom notes on at least 33 machines. Criteria: Confirm impact by correlating payload execution with file encryption and inaccessibility. Do not confirm complete encryption based solely on filenames, ransom notes, or process launches; tally affected host counts independently.
  • Scope: Affected endpoints and servers
  • Related CVEs: None

10. Investigation Playbook

Trigger

  • Initiate investigations upon encountering SharePoint alerts, webshells, driver loads, EDR terminations, SYSVOL modifications, or ransom notes.

Initial Verification

  • Inspect externally exposed SharePoint instances, patch status, IIS logs, w3wp process trees, AD permissions, SYSVOL deltas, and the count of impacted hosts.

Endpoints

  • Preserve webshells, sideloading pairs, code-insiders services, drivers, hash values, and ransomware payloads.

Authentication & Cloud

  • Investigate compromised accounts, privileged groups, service accounts, Visual Studio Code tunnel accounts, and tokens.

Subsequent Actions

  • Track data exfiltration, backup destruction, persistence mechanisms, additional domains, and impacts on critical services.

Containment

  • Isolate SharePoint servers, halt unauthorized writes to SYSVOL, preserve evidence before deleting malicious files, rotate compromised account credentials and cryptographic keys, and isolate affected network segments.

Judgment Criteria

  • Differentiate between attack attempts, successful webshell deployment, domain privilege acquisition, security feature disabling, SYSVOL-based distribution, and file encryption.

11. Defense and Detection Ideas

Single Event

  • Treat suspicious Portable Executable (PE) file creation within the SYSVOL scripts path, file placement via dfsrs.exe, and vulnerable driver loading as high priority. Do not conflate the process writing the file with the parent process executing the PE.

Time-Series Correlation

  • Correlate the chain of events: w3wp webshell deployment -> domain reconnaissance -> DLL sideloading / Visual Studio Code tunneling -> driver loading -> security process termination -> SYSVOL writes -> distribution via dfsrs.exe -> encryption.

Hunting Perspective

  • Search for public hashes, code-insiders.exe service registrations, run.exe / rune.exe, how to restore your files.txt, and network IOCs. Recognize that K7RKScan indicators stem from a separate recent attack and should not be assumed to be the driver used in this specific intrusion.

Log Gaps

  • Initial access CVEs are unconfirmed; do not rely solely on SharePoint exploit signatures. Where SYSVOL audit logs are absent, supplement investigation using domain controller file systems and DFS telemetry.

Priority Mitigations

  • Prioritize patching or isolating SharePoint, monitoring SYSVOL, blocking vulnerable drivers, enforcing application control, and verifying AD and backup recovery procedures.

12. Facts / Inference / Hypothesis

Facts

  • Symantec assesses Longlegs (Storm-2603) as an attacker linked to China, reporting attacks against at least four organizations across water, telecommunications, local government, and universities over the past two months. CL-CRI-1040, CamoFei, and ChamelGang are activity clusters previously associated by Symantec and are not assumed here to be identical synonyms.
  • Initial access likely involved exploiting SharePoint vulnerabilities; subsequent to webshell deployment, actors performed reconnaissance, DLL sideloading, and credential/domain discovery. The four related CVEs listed reflect historical ToolShell activity and do not confirm the specific CVE exploited in recent intrusions.
  • In the detailed intrusion at a critical infrastructure organization, a Visual Studio Code tunnel was registered as a service. AV/EDR Killer execution was subsequently recorded on at least 40 hosts within approximately two hours. Use of a vulnerable driver in this intrusion was suspected, but the driver was not identified.
  • In the same intrusion, run.exe, rune.exe, and ransom notes were recorded on at least 33 hosts. The report also provides a command that copies the payloads from SYSVOL and launches them. Telemetry from three other hosts recorded payload placement by dfsrs.exe. DC-to-DC replication does not establish execution or completed encryption on every endpoint; the counts of 33 and 3 should not be combined into a total of hosts with confirmed ransomware execution or encryption.
  • Japan has also been cited as a target country in past Warlock campaigns.

Inference

  • Payload staging in SYSVOL may be missed by lateral movement monitoring focused primarily on PsExec or WMI. Monitor DFS replication activity and changes to the SYSVOL scripts directory as well.
  • Discovery of a SharePoint webshell warrants broad investigation for potential domain compromise. However, the mere presence of a webshell does not confirm domain privilege acquisition or enterprise-wide breach status.

Hypothesis

No additional hypotheses. Unconfirmed items are detailed in Section 14, "Open Questions and Further Investigation."

13. MITRE ATT&CK Mapping

ID Technique Confidence Basis
T1190 Exploit Public-Facing Application medium Recent intrusions are reported to have likely used SharePoint vulnerability exploitation for initial access.
T1574.001 Hijack Execution Flow: DLL high Pairs of legitimate executables and malicious DLLs are deployed and executed.
T1562.001 Impair Defenses: Disable or Modify Tools high Execution of AV/EDR Killers has been recorded. Use of a vulnerable driver in the detailed intrusion is suspected, and K7RKScan was observed in a separate recent attack.
T1219.001 Remote Access Tools: IDE Tunneling high Registration of remote access services via Visual Studio Code tunnel service installation was recorded. This is distinct from T1021.007, which involves logging into a victim's cloud services.
T1486 Data Encrypted for Impact high Warlock payloads, ransom notes, and execution commands were reported. This maps deployment aimed at encryption and does not indicate completed encryption across all distribution targets.

14. Open Questions and Further Investigation

  • Identification of the specific SharePoint CVEs exploited in the four recent intrusions.
  • Presence of data exfiltration, encryption scopes, and recovery statuses across each organization.
  • The specific command relationship, if any, between Longlegs and state organizations.
  • Identification of the driver used by the AV/EDR Killer in the detailed intrusion, the mechanism launching distribution commands on each host, and the count of successfully encrypted machines.

15. Impact on SOCs and Organizations

Japan has also been cited as a target country in past campaigns. Organizations operating internet-facing SharePoint servers should treat anomalies involving webshells or IIS worker processes not merely as isolated server issues, but should investigate potential AD trust discovery, driver loading, Visual Studio Code tunnel services, SYSVOL modifications, and DFS replication distribution as part of a connected intrusion campaign. Critical infrastructure entities such as water and telecommunications operators must pre-emptively prepare containment procedures that account for operational impacts caused by domain service outages.

16. Summary by Role

  • SOC: Correlate SharePoint webshells, DLL sideloading, Visual Studio Code tunnels, AV/EDR Killers, and SYSVOL modifications. Verify file placement via dfsrs.exe and subsequent Warlock execution/encryption on individual hosts using separate evidence.
  • Administrators: Apply updates or isolate SharePoint, monitor changes to the SYSVOL scripts directory, control driver usage, restrict Visual Studio Code tunneling, and ensure offline backups are available.
  • Users: If you encounter suspicious files or ransom notes, stop using the affected device, disconnect it from the network, and contact your internal security team.

Top comments (0)