TL;DR
- what: Warlock (Longlegs) broke into on-premises SharePoint servers at a water utility, a telecom provider, a regional government body and a university over two months, using the ToolShell vulnerabilities.
- impact: In one intrusion the group used a vulnerable K7RKScan driver to disable protection software on at least 40 hosts in about two hours, then pushed Warlock ransomware to 33 hosts from the domain SYSVOL share.
- fix: Microsoft released fixes for CVE-2025-49704, CVE-2025-49706, CVE-2025-53770 and CVE-2025-53771 in July 2025, and its ToolShell guidance also calls for rotating SharePoint ASP.NET machine keys after patching.
- who: Organizations running internet-facing on-premises SharePoint, especially utilities, telecoms, governments and universities in Portuguese- and Spanish-speaking countries across Europe, Africa and Latin America.
A China-linked ransomware group got into a water utility and a telecom provider through SharePoint vulnerabilities that were patched more than a year ago. According to Symantec and Carbon Black researchers, the Warlock operation, which Symantec tracks as Longlegs, hit four organizations over two months: a water utility, a telecom provider, a regional government body and a university. In one intrusion the attackers disabled protection software on at least 40 hosts in about two hours, then deployed ransomware to 33 of them.
The targeting centered on Portuguese- and Spanish-speaking countries across Europe, Africa and Latin America. The entry point was the same one Warlock used when it first appeared in June 2025: ToolShell, a set of on-premises SharePoint flaws.
Initial Access: ToolShell, Still Working
ToolShell covers four CVEs: CVE-2025-49704, CVE-2025-49706, CVE-2025-53770 and CVE-2025-53771. They were exploited as zero-days in July 2025, mass exploitation followed, and Microsoft shipped fixes that month. Chaining them gives an unauthenticated attacker code execution on on-premises SharePoint Server. SharePoint Online is not affected.
The researchers found web shells planted across several SharePoint versions in these intrusions. They said ToolShell and other SharePoint vulnerabilities "remain viable initial access vectors, more than a year after Warlock first emerged." Put simply, internet-facing SharePoint servers at critical infrastructure operators are still unpatched, or were patched without the follow-up steps that lock attackers out.
⚠️ Patching alone does not evict an attacker — ToolShell exploitation was used to steal SharePoint ASP.NET machine keys. A server that was patched after it was compromised can still accept forged requests signed with the stolen keys. Microsoft's ToolShell guidance pairs the security updates with machine key rotation and an IIS restart for this reason.
The Intrusion Chain
The best-documented intrusion started on July 22 and reached its final stage on July 31. In those nine days the attackers went from a SharePoint foothold to domain-wide ransomware deployment using a small, familiar toolkit:
- Web shells on the compromised SharePoint servers for persistent command execution.
- Visual Studio Code Insiders installed as a Windows service, abusing its built-in remote tunneling feature for interactive access that looks like legitimate developer traffic.
- NetExec, an open-source penetration testing framework, for Active Directory enumeration and credential spraying.
- A BYOVD (bring your own vulnerable driver) EDR killer built on the K7RKScan driver, tracked as CVE-2025-1055.
- Warlock ransomware staged in the domain SYSVOL share for network-wide execution.
None of these tools is new. VS Code tunneling has turned up in several state-linked intrusions as a C2 channel that blends in. NetExec is a common red team tool. What stands out is the speed: once the attackers had domain credentials, they moved from defense evasion to encryption within hours.
Killing EDR at Scale With a Signed Driver
The BYOVD step decided how much damage the attack would do. CVE-2025-1055 is a flaw in K7RKScan, a legitimately signed kernel driver from the K7 security product line. Because Windows loads the signed driver, the attackers get kernel-level access they can use to kill security processes that would block any user-mode attempt.
The researchers say the tool disabled protection software on at least 40 hosts in about two hours. That rate points to automated deployment over the domain, not hands-on work host by host. Once endpoint telemetry went dark across that many machines, the defenders lost visibility right before encryption started.
SYSVOL as a Distribution Point
The ransomware was staged in the domain SYSVOL share. Every domain-joined machine reads SYSVOL, and it holds logon scripts and Group Policy objects. The researchers noted that this allows "pushing a payload out for execution by a logon script or Group Policy object across an entire network." An attacker with the right Active Directory privileges can turn the domain's own management system into the delivery mechanism, which is how 33 hosts were encrypted in one push.
Detection signals from this campaign — Researchers flagged these artifacts: new executables written to SYSVOL outside change windows, Visual Studio Code Insiders registered as a service on servers, the K7RKScan driver loading on hosts that do not run K7 products, NetExec-style authentication spraying against domain controllers, and web shells in SharePoint layouts directories.
Why Critical Infrastructure Should Pay Attention
A water utility and a telecom provider are not typical ransomware targets picked for a quick payout. Both run IT environments that sit next to operational systems, and in both a domain-wide outage can disrupt services the public depends on. The source does not report any OT impact, but SharePoint servers at these operators often hold engineering documents, network diagrams and vendor credentials. That information is useful to a state-linked actor whether or not ransomware is ever deployed.
Warlock's China nexus and its focus on regional government and university networks match a pattern of financially motivated tooling run alongside intelligence-gathering goals. Ransomware may be the visible end of these intrusions, not their only purpose.
Vendor Fix and Mitigation
Microsoft fixed all four ToolShell CVEs in its July 2025 security updates for SharePoint Server Subscription Edition, SharePoint Server 2019 and SharePoint Server 2016. Its guidance also covers rotating ASP.NET machine keys, enabling AMSI integration with Defender on SharePoint, and treating any server exposed before patching as possibly compromised. Microsoft's vulnerable driver blocklist is the vendor-side control for BYOVD abuse. Whether it covers a given vulnerable driver version depends on the blocklist release, so confirm that with Microsoft.
RedEye Assessment
This campaign shows that the ToolShell patch window never fully closed. Organizations that patched in 2025 but did not rotate keys, hunt for web shells or check for persistence may still have an attacker inside. RedEye Security can assess your SharePoint exposure, review Active Directory and SYSVOL for staging artifacts, and test whether your endpoint protection holds up against BYOVD tampering. Contact RedEye to schedule an assessment before a nine-day intrusion becomes a domain-wide outage.
Originally published on RedEye Threat Intelligence.
Top comments (0)