FR
live

Warlock ransomware walks through critical-infrastructure SharePoint a year after the ToolShell zero-days

A year after the ToolShell SharePoint zero-days, the China-linked Warlock group — tracked as Longlegs by Symantec — hit a water utility, a telecom operator, a regional government, and a university, disabling protection on 40 machines in two hours. Patch your on-prem SharePoint, monitor BYOVD driver loads, and hunt the indicators published by Symantec and Carbon Black.

An industrial control panel of a water treatment station, dark and unpowered, a single amber alarm lamp lit on top.

June 2025. Warlock, a China-linked ransomware strain, emerges and, a month later, makes its name exploiting the ToolShell chain of SharePoint zero-days. 22 July 2026. In an intrusion dissected by Symantec, the group disables protection on 40 machines in two hours before deploying its ransomware on 33 of them. 2 October 2026. Symantec and Carbon Black publish a full analysis and indicators of compromise. Why it matters: more than a year after the patches, the SharePoint flaws remain the preferred entry point of a group targeting water, telecoms, and government.

A target set that has changed in nature

The report from Symantec and Carbon Black — who track the actor as Longlegs — describes a clear shift in targeting. For about two months, Warlock has focused on organizations in Portuguese- and Spanish-speaking countries across Europe, Africa, and Latin America, and on sectors that go beyond the usual ransomware victim trio. A water utility, a telecom operator, a regional government body, and a university are among the confirmed targets.

That choice is not trivial. Critical infrastructure and public bodies are both more sensitive and often less well defended than large private enterprises, while offering the same negotiating leverage — a service interruption that is immediately priced. The group, which emerged in June 2025, first built its notoriety in July 2025 by exploiting ToolShell, a chain of four zero-day flaws in Microsoft SharePoint tracked as CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771.

ToolShell, a year later, is still the door in

The most striking point of the report is the persistence of the vector. In August 2026, Microsoft observed the state-backed groups Linen Typhoon and Violet Typhoon using the same ToolShell exploits, alongside a ransomware actor the vendor tracks as Storm-2603. In other words, a year after disclosure and patching, the SharePoint flaws still serve as the initial access point, including for actors who do not even need a zero-day to get in.

The mechanics are classic. The attacker exploits a flaw in an on-prem SharePoint to drop a web shell compatible with multiple product versions, then uses it to pivot into the domain. The danger is less the flaw itself than the unpatched surface: every exposed or lagging SharePoint server is a potential entry point, and Warlock knows it.

An “EDR killer” pushed to 40 hosts in two hours

The intrusion of 22 July 2026 is the most technical, and most alarming, piece. Two days after initial access, the attacker ran reconnaissance and deleted staging artifacts. On 31 July, it deployed a protection-disabling tool that neutralized antivirus and EDR on at least 40 hosts in about two hours, before Warlock ransomware appeared “almost as soon as protection was disabled on each host”, on 33 machines.

The disabling technique relies on BYOVD — bring your own vulnerable driver. The attacker loads a signed K7RKScan driver, vulnerable to CVE-2025-1055, to gain the privileges needed to neutralize defenses. This is the flaw in Windows’ trust model: a signed-but-vulnerable driver is accepted by the kernel, then exploited to disarm the defenses. The operational lesson is direct — block known-vulnerable drivers and monitor abnormal driver loads. The two-hour window is the number that should worry defenders most: once the driver lands, the time between “protection still active” and “ransomware running” is measured in minutes per host, leaving no room for a human-in-the-loop response.

SYSVOL, VS Code, and NetExec: a deployment that bypasses silos

The ransomware deployment shows deep Active Directory knowledge. The payload was staged in the SYSVOL share, a public location replicated to every domain controller. That is, the researchers say, a known method for pushing a payload across an entire network at once, via a logon script or Group Policy, rather than host by host.

For persistence and lateral movement, the attacker installed the main Visual Studio Code Insiders executable as a service, to use VS Code’s built-in tunneling to reconnect to compromised machines. On one system, the researchers also found NetExec, an open-source penetration-testing framework used for Active Directory enumeration, credential spraying, and remote command execution. Together they draw a picture of an operator that does not just encrypt: it establishes itself, then strikes.

Blocking BYOVD drivers is a policy, not a product

The BYOVD technique has been known for years, and the defense exists. Microsoft maintains a vulnerable driver blocklist, applied by default on Windows 11 through Microsoft Defender’s vulnerable-driver protection. But on heterogeneous estates — and especially on SharePoint servers, which often run Windows Server — that protection is not always active, or does not cover every older signed driver.

The K7RKScan driver illustrates the problem. The driver is signed, so the kernel accepts it, but it carries an exploitable vulnerability (CVE-2025-1055) the attacker uses to neutralize defenses. Blocking that driver means enabling vulnerable-driver blocking and keeping the list current — a configuration policy, not a feature that installs itself. On critical infrastructure, it is nonetheless the only way to counter Warlock’s speed, which disables 40 machines in two hours.

Why on-prem SharePoint remains a target

The ToolShell vector would not be as effective if on-prem SharePoint servers were not still widely deployed. Many organizations keep an internal SharePoint for compliance reasons, for dependencies on line-of-business applications, or simply through inertia — servers that fall off the security team’s radar but remain reachable on the internal network. That is exactly the surface Warlock exploits: a flaw patched a year ago, but an estate that was never updated, and an entry point the researchers describe as “still viable” more than a year after the group emerged.

What to do

The response comes down to five actions, in order.

  • 1. Patch SharePoint. Apply the ToolShell fixes to every on-prem SharePoint server, including ones that seem unused. This is Warlock’s initial entry point, and it remains exploitable a year on.
  • 2. Block BYOVD drivers. Deploy blocking for known-vulnerable drivers — starting with K7RKScan (CVE-2025-1055) — and enable driver-load logging.
  • 3. Watch SYSVOL. Inspect the SYSVOL share and Group Policy for unexpected binaries or modified logon scripts.
  • 4. Restrict tunnels. Control the use of VS Code and its tunnels in the fleet, and block unapproved executables installed as services.
  • 5. Hunt the IOCs. Cross-reference the indicators of compromise published by Symantec and Carbon Black against your logs, prioritizing water, telecom, and government sectors.

Verdict

If you run on-prem SharePoint, treat ToolShell as an open debt and immediately check the patch state of every server: Warlock walks through that door a year later, and it is not alone. If you manage critical infrastructure or a public body, consider your sector now on the target list and harden EDR visibility — the group disables 40 machines in two hours, a speed that requires detecting BYOVD drivers upstream, not after the fact. If you think ransomware is a big-enterprise problem, this case shows otherwise: water, telecoms, and government are on the front line, with a vector that a late patch alone cannot close.

References

The cyber brief, every Tuesday

The flaws that matter and the patches to apply, in a ten-minute read.

No spam. One-click unsubscribe.
read next

On the same topic

Citrix urges patching a NetScaler RCE flaw that hits SAML-configured appliances

On October 9, 2026, Citrix shipped a fix for CVE-2026-107406, a memory-overflow bug that lets an attacker run code remotely or crash NetScaler ADC and Gateway appliances configured as a SAML identity provider or service provider. Upgrade to 14.1-73.46 or 13.1-64.29, or drop the SAML configuration if you do not use it.

← Back to the feed

Type at least two characters.

↑ ↓ navigate ↵ open esc dismiss