Warlock Uses On-Premises SharePoint to Deploy Ransomware on at Least 33 Hosts

China-linked Warlock ransomware exploited on-premises SharePoint flaws to breach utilities and governments, deploying ransomware on 33+ hosts via SYSVOL.

Warlock Uses On-Premises SharePoint to Deploy Ransomware on at Least 33 Hosts
Ransomware

Illustrative image generated with AI

Listen to this articleAudio edition · 11 min

A China-linked ransomware group known as Warlock targeted a water utility, a telecommunications provider, a regional government body and a university by exploiting vulnerabilities in on-premises Microsoft SharePoint deployments, BleepingComputer reported on October 2, 2026.

The report says that, over the preceding two months, the group appeared to focus on Portuguese- and Spanish-speaking countries across Europe, Africa and Latin America. Symantec identifies the actor as Longlegs and attributes the development of Warlock ransomware to the group. The intrusion findings are attributed to Symantec and Carbon Black researchers.

In one investigation, attackers gained initial access on July 22; the report does not specify the year. They disabled security protections on at least 40 hosts within about two hours, then deployed ransomware on at least 33. The final stage occurred on July 31, also without a year specified.

SharePoint flaws provided an initial-access route

The researchers said Longlegs typically gained access by exploiting vulnerabilities in on-premises SharePoint deployments. After entry, the attackers installed a web shell designed to work across multiple SharePoint versions.

Warlock emerged in June 2025 and gained prominence the following month after exploiting a SharePoint zero-day chain known as ToolShell. The report discusses CVE-2025-49704, CVE-2025-49706, CVE-2025-53770 and CVE-2025-53771 as SharePoint vulnerabilities. The reporting does not establish that every one of these vulnerabilities was used in the specific intrusion described.

ToolShell activity has also been attributed to other actors. The report says Microsoft observed state-backed groups Linen Typhoon and Violet Typhoon using the exploits by August, alongside a ransomware actor it tracks as Storm-2603. These are separate actors; the report does not identify them as Warlock or Longlegs.

The four flaws differ in impact and affected versions:

CVE NVD description and score Affected products and versions listed
CVE-2025-49704 Code injection allowing an authorized attacker to execute code over a network; CVSS 8.8, CWE-94 Microsoft SharePoint Server 2016
CVE-2025-49706 Improper authentication allowing network spoofing; CVSS 6.5, CWE-287 Microsoft SharePoint Enterprise Server 2016; Microsoft SharePoint Server versions earlier than 16.0.18526.20424
CVE-2025-53770 Deserialization of untrusted data allowing an unauthorized attacker to execute code over a network; CVSS 9.8, CWE-502 Microsoft SharePoint Server versions earlier than 16.0.18526.20508
CVE-2025-53771 Improper authentication allowing network spoofing; CVSS 6.5, CWE-287 Microsoft SharePoint Server versions earlier than 16.0.18526.20508

For CVE-2025-53770, Microsoft said an exploit existed in the wild and advised applying the mitigation documented for the CVE while it prepared and tested a comprehensive update. The supplied vulnerability data marks CVE-2025-49704, CVE-2025-49706 and CVE-2025-53770 as used in ransomware campaigns.

SYSVOL and remote-access tools supported later activity

In the investigated intrusion, attackers performed reconnaissance two days after initial access and deleted artifacts researchers assessed as possible staging material.

They placed the ransomware payload in the domain’s SYSVOL share, which stores public files and replicates across domain controllers. Researchers described logon scripts or Group Policy objects as ways to distribute and execute a payload across a network, rather than handling hosts one at a time. The report confirms ransomware execution on at least 33 hosts in this incident; it does not say the entire domain was infected.

The attackers also installed the main executable for Visual Studio Code Insiders as a service. That allowed remote connections to compromised machines through the application’s built-in tunneling capability.

Researchers found NetExec, an open-source penetration-testing framework, on one system. In the reported activity, it was used for Active Directory enumeration, credential spraying and remote command execution.

BYOVD was used to interfere with security software

In some attacks attributed to Longlegs, researchers observed an antivirus and endpoint-detection-and-response killer delivered using the bring your own vulnerable driver (BYOVD) technique. The driver was a signed K7RKScan.sys, part of the K7 Security Anti-Malware suite, affected by CVE-2025-1055.

The vulnerability has a CVSS v3.1 score of 5.6 and is classified as CWE-862. The NVD describes missing access control in the driver’s IOCTL handler: a local user with low privileges can send crafted requests that terminate a broad range of processes running with administrative or system-level privileges. Processes inherently protected by the operating system are excepted. The NVD characterizes the potential impact as denial of service through disruption of critical services or privileged applications.

The researchers’ account concerns the driver’s use in some Longlegs-attributed attacks to deliver a tool that killed AV/EDR protections. That observed use is distinct from the NVD’s description of the vulnerability’s technical impact.

CISA KEV listings carry separate deadlines

The supplied data lists CVE-2025-53770 in CISA’s Known Exploited Vulnerabilities catalog from 2025-07-20, with a 2025-07-21 remediation deadline for U.S. federal agencies. CVE-2025-49704 and CVE-2025-49706 were listed from 2025-07-22, with a 2025-07-23 deadline for those agencies. The supplied data does not provide KEV listing or deadline information for CVE-2025-53771.

For these three KEV-listed SharePoint vulnerabilities, CISA directs organizations to disconnect public-facing SharePoint Server installations that have reached end of life or end of service, including SharePoint Server 2013 and earlier. For supported versions, its direction is to follow CISA mitigations and vendor instructions. It also says to adhere to applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.

Other Microsoft vulnerabilities have also been added to KEV in the preceding 90 days: CVE-2026-65660 on 2026-09-25; CVE-2026-85880 and CVE-2026-81963 on 2026-09-08; CVE-2019-1068 on 2026-08-26; and CVE-2026-55040 and CVE-2026-33824 on 2026-08-18. These entries provide vendor-level context, not evidence of a connection to Warlock.

What defenders can check

Organizations can inventory their SharePoint deployments and compare installed versions with the affected ranges listed above. For public-facing servers that have reached end of life or end of service, CISA’s direction is to disconnect them; supported deployments should follow the agency’s mitigations and vendor instructions. For CVE-2025-53770, Microsoft’s supplied guidance specifically calls for putting the mitigation documented for that CVE in place.

The reported activity also gives security teams behaviors to examine: web shells on SharePoint systems, unexpected files or payloads in SYSVOL, unusual logon scripts or Group Policy activity, and service installation involving Visual Studio Code Insiders. On endpoints, teams can investigate NetExec use, credential spraying, remote command execution, unexpected K7RKScan.sys activity and abrupt termination of security processes. These are checks based on the described intrusion, not a claim that every Warlock operation uses the same methods.

BleepingComputer says the Symantec and Carbon Black report includes indicators of compromise for files and infrastructure. The supplied article material does not reproduce the indicator values, so no hashes, domains or IP addresses can be listed here.

Read next

Sources

This article is an original reworking based on the sources below.

CVEs covered in this article

Back to home

Latest Cybersecurity News

All cybersecurity news →