CyberIncidents Logo
Cyber News

Warlock Ransomware Exploits Microsoft SharePoint Flaws to Disable Security Tools and Deploy Ransomware

Threat Actor: Warlock / Longlegs / Storm-2603 / Gold Salem

Rohith HariOctober 3, 20268 min read
Warlock Ransomware Exploits Microsoft SharePoint Flaws to Disable Security Tools and Deploy Ransomware

Overview

A suspected China-linked threat actor tracked as Warlock, also known as Longlegs and Storm-2603, is continuing to exploit vulnerabilities in on-premises Microsoft SharePoint Server environments to gain initial access, disable security controls, move laterally, and deploy ransomware.

According to research from the Symantec and Carbon Black Threat Hunter Team, the recent campaign has affected at least four organizations in Portuguese- and Spanish-speaking countries across Europe, Africa, and Latin America. The victims included a water utility, telecommunications provider, regional government organization, and university.

The campaign demonstrates how a single vulnerable internet-facing SharePoint server can become the entry point for a much broader domain-wide ransomware attack.

CyberIncidents article image

How the Attack Works

The observed attack chain follows several stages:

SharePoint exploitation → Web shell → Credential/key theft → Remote code execution → Reconnaissance → Lateral movement → Security-tool disabling → Ransomware deployment

1. Exploiting SharePoint Vulnerabilities

Warlock has continued to use vulnerabilities affecting on-premises Microsoft SharePoint Server deployments.

The threat actor gained access by exploiting SharePoint flaws and subsequently placing a web shell within the SharePoint environment.

The attackers then targeted the SharePoint application's ASP.NET machine keys. These keys can be abused to forge validly signed payloads and achieve remote code execution within the SharePoint application pool.

The campaign is associated with the broader ToolShell exploitation activity that brought Warlock to prominence in 2025.

2. Web Shell and Remote Code Execution

After gaining access, attackers deployed web shells designed to work across multiple SharePoint versions.

The web shell provided a foothold for additional commands and allowed the attackers to progress from the compromised SharePoint server toward broader network access.

Observed activity included:

  • PowerShell execution

  • System and domain reconnaissance

  • SharePoint application-pool code execution

  • Downloading additional payloads

  • Active Directory enumeration

  • Credential-related activity

  • Lateral movement

3. Living-off-the-Land Techniques

Rather than relying exclusively on custom malware, the attackers used legitimate Windows utilities to perform reconnaissance and execute commands.

Observed tools included:

  • whoami

  • net

  • nltest

  • PowerShell

  • msiexec

  • NetExec

This approach can make malicious activity more difficult to distinguish from legitimate administrative operations.

For SOC teams, the important signal is often not the presence of these tools individually, but the sequence and context in which they are executed.

For example:

SharePoint worker process → PowerShell → reconnaissance → payload download → domain enumeration → remote access → security-tool termination

That sequence is considerably more suspicious than an isolated administrative command.

4. DLL Sideloading

The attackers also used DLL sideloading to execute malicious code through legitimate executable files.

This technique can allow malicious code to execute while appearing to originate from a trusted or expected binary.

The observed intrusion included executable/DLL pairs such as:

  • ssvagent.exe

  • logger.exe

  • doexe.exe

  • doexeloc.dll

This activity highlights the importance of monitoring unusual executable/DLL relationships rather than relying only on known malware hashes.

5. Abuse of Legitimate Cloud Services

Warlock also downloaded follow-on payloads from legitimate cloud-hosting and file-sharing infrastructure.

Researchers observed infrastructure associated with services including:

  • catbox[.]moe

  • wasabisys[.]com

Using legitimate hosting providers can provide attackers with an additional layer of operational camouflage because connections to popular cloud services may not immediately appear malicious.

SOC teams should therefore correlate process execution + outbound connection + downloaded file + subsequent behavior, rather than automatically trusting a destination because it belongs to a legitimate hosting provider.

6. BYOVD: Disabling Security Software

One of the most concerning stages of the attack involved Bring Your Own Vulnerable Driver (BYOVD).

The attackers were observed abusing K7RKScan.sys, a legitimate signed but vulnerable driver associated with CVE-2025-1055, to interfere with security software.

The purpose was to neutralize defensive controls before ransomware deployment.

This is particularly dangerous because the attacker does not necessarily need to exploit a new kernel vulnerability. Instead, they can abuse a legitimately signed vulnerable driver to obtain capabilities that allow them to terminate or interfere with protected security processes.

7. Visual Studio Code Tunnel Abuse

Another notable technique was the abuse of Visual Studio Code's tunnel functionality.

The attackers installed a VS Code Insiders binary as a service and used its tunnel functionality to establish remote connectivity to compromised systems.

Because Visual Studio Code is legitimate software and its infrastructure is associated with Microsoft, this technique can potentially blend into normal enterprise traffic.

For defenders, this reinforces the need to monitor:

  • Unexpected VS Code installations

  • code-insiders.exe running as a service

  • Tunnel creation on servers

  • Developer tools appearing on non-development systems

  • Unusual outbound connections initiated by server processes

8. SYSVOL Used to Scale Ransomware Deployment

The attackers eventually moved from individual compromised hosts to domain-wide ransomware deployment.

One particularly notable technique involved staging ransomware payloads inside the domain's SYSVOL share.

SYSVOL is normally used by Active Directory to distribute files associated with Group Policy and logon processes.

Because SYSVOL is replicated between domain controllers and accessible across the domain, attackers can abuse it as a distribution mechanism.

In one observed intrusion:

  • Security-disabling tools were pushed to at least 40 hosts

  • Warlock ransomware subsequently appeared on at least 33 hosts

  • Ransomware payloads were staged through the domain's SYSVOL infrastructure

This allowed the attackers to move from compromising a small number of systems to impacting a significant portion of the environment in a short period.

Attack Chain

A simplified representation of the observed campaign is:

Internet-facing SharePoint Server

↓

SharePoint vulnerability exploitation

↓

Web shell deployment

↓

ASP.NET machine-key abuse

↓

Remote Code Execution

↓

PowerShell / Windows reconnaissance

↓

Payload download

↓

DLL sideloading

↓

Active Directory enumeration

↓

Lateral movement

↓

VS Code Tunnel / remote access

↓

BYOVD / security-tool termination

↓

SYSVOL payload staging

↓

Domain-wide ransomware deployment

CyberIncidents article image

Why This Attack Matters

The campaign demonstrates that ransomware operations are increasingly combining vulnerability exploitation, legitimate administrative tools, defense evasion, and domain-level deployment mechanisms.

The initial compromise may begin with a single exposed SharePoint server, but the final impact can extend across an organization's entire Active Directory environment.

The use of SYSVOL is particularly significant because it provides attackers with a mechanism for distributing malicious files at scale.

The campaign also shows why simply detecting the ransomware binary may be too late. By the time ransomware is executed, attackers may already have:

  • Compromised an internet-facing server

  • Established persistence

  • Enumerated the domain

  • Obtained credentials or authentication material

  • Moved laterally

  • Disabled security products

  • Prepared ransomware distribution

What SOC Teams Should Monitor

Organizations running on-premises SharePoint should prioritize monitoring for:

SharePoint

  • Unexpected .aspx files in SharePoint directories

  • Web shells

  • Suspicious SharePoint worker-process activity

  • Unexpected PowerShell spawned by SharePoint processes

  • ASP.NET machine-key-related anomalies

  • Outbound connections initiated by SharePoint servers

Endpoint

  • Unsigned or unusual DLL loading

  • DLL sideloading patterns

  • msiexec.exe downloading packages from external URLs

  • Suspicious PowerShell execution

  • Unexpected code-insiders.exe activity

  • VS Code tunnel creation on servers

  • Security products unexpectedly stopping or being disabled

Active Directory

Monitor unusual execution of:

  • nltest

  • net

  • NetExec

  • Remote administrative commands

  • Unexpected local administrator-group modifications

  • Newly created or suspiciously named accounts

SYSVOL

SOC teams should pay particular attention to unexpected files appearing in:

\\<domain>\SYSVOL\

Especially:

  • .exe

  • .dll

  • .bat

  • .ps1

  • .cmd

  • Unknown scripts or binaries

Unexpected executable files in SYSVOL should be treated as a high-priority investigation.

Key Defensive Takeaways

1. Patch internet-facing SharePoint servers quickly.
SharePoint vulnerabilities can provide attackers with an initial foothold into the enterprise.

2. Do not rely only on malware signatures.
Warlock's activity includes legitimate tools and native Windows utilities.

3. Monitor defense-evasion behavior.
Unexpected attempts to terminate EDR/AV processes or load vulnerable drivers should generate high-priority alerts.

4. Protect Active Directory and SYSVOL.
Once attackers obtain domain-level access, SYSVOL can become an effective mechanism for distributing malicious payloads.

5. Investigate attack chains, not isolated alerts.
A single whoami or nltest command may be legitimate. The same commands following SharePoint exploitation and web-shell activity are significantly more concerning.

CyberIncidents article image


The continued activity associated with Warlock/Longlegs shows that unpatched SharePoint infrastructure remains a valuable entry point for ransomware operators.

The most important lesson for defenders is that ransomware deployment is often the final stage of a much longer intrusion.

Organizations should focus on detecting the earlier stages of the attack chain—SharePoint exploitation, web shells, suspicious PowerShell, DLL sideloading, Active Directory reconnaissance, vulnerable-driver abuse, and unusual SYSVOL activity—before attackers reach the ransomware deployment stage.

According to Symantec and Carbon Black, the recent activity represents continued exploitation of SharePoint vulnerabilities more than a year after Warlock first became prominent.

MITRE ATT&CK Techniques Potentially Relevant

  • T1190 — Exploit Public-Facing Application

  • T1505.003 — Web Shell

  • T1059.001 — PowerShell

  • T1574.002 — DLL Side-Loading

  • T1087.002 — Domain Account Discovery

  • T1018 — Remote System Discovery

  • T1489 — Service Stop

  • T1562.001 — Impair Defenses

  • T1078 — Valid Accounts

  • T1021 — Remote Services

  • T1105 — Ingress Tool Transfer

  • T1486 — Data Encrypted for Impact

Filed under Cyber News