Full Report
The China-linked ransomware group Warlock targeted a water utility, a telecom provider, a regional government body, and a university by exploiting SharePoint vulnerabilities to gain initial access. [...]
Analysis Summary
# Incident Report: Warlock Ransomware Exploitation of SharePoint Vulnerabilities
## Executive Summary
The China-linked threat actor Warlock (also tracked as Longlegs/Storm-2603) targeted critical infrastructure, government, and educational sectors by exploiting a chain of SharePoint zero-day vulnerabilities known as "ToolShell." The attacks utilized sophisticated evasion techniques, including a "Bring Your Own Vulnerable Driver" (BYOVD) EDR killer and Visual Studio Code tunneling for persistence. The campaign resulted in the deployment of Warlock ransomware across multiple organizations in Portuguese and Spanish-speaking regions.
## Incident Details
- **Discovery Date:** July 22, 2026 (Initial activity detected)
- **Incident Date:** July - August 2026
- **Affected Organization:** Multiple (Water utility, Telecom provider, University, Regional government)
- **Sector:** Critical Infrastructure, Telecommunications, Government, Education
- **Geography:** Europe, Africa, and Latin America (Portuguese/Spanish speaking regions)
## Timeline of Events
### Initial Access
- **Date/Time:** July 22, 2026
- **Vector:** Exploitation of Microsoft SharePoint vulnerabilities.
- **Details:** Use of the "ToolShell" vulnerability chain (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771) to gain remote code execution (RCE).
### Lateral Movement
- **Reconnaissance:** Performed two days after initial access; utilized the NetExec framework for Active Directory enumeration and credential spraying.
- **Persistence:** Installed Visual Studio Code Insiders as a service to leverage built-in tunneling for remote access.
- **Staging:** Ransomware payload was staged in the domain’s **SYSVOL** share to facilitate mass execution via Group Policy Objects (GPO).
### Data Exfiltration/Impact
- **EDR Neutralization:** Deployed a tool to disable security software on 40+ hosts within a two-hour window.
- **Encryption:** Deployed Warlock ransomware to at least 33 hosts immediately following EDR termination.
### Detection & Response
- **Discovery:** Identified by security researchers (Symantec and Carbon Black) monitoring for SharePoint exploitation.
- **Response Actions:** Artifact deletion by the threat actor suggested awareness of monitoring; researchers published IOCs to facilitate industry-wide containment.
## Attack Methodology
- **Initial Access:** Exploitation of SharePoint "ToolShell" zero-days; deployment of a cross-version web shell.
- **Persistence:** Visual Studio Code tunneling capability; web shells.
- **Privilege Escalation:** Exploitation of CVE-2025-1055 via a signed K7RKScan driver.
- **Defense Evasion:** Bring Your Own Vulnerable Driver (BYOVD) to kill AV/EDR processes; deletion of staging artifacts.
- **Credential Access:** Credential spraying via NetExec.
- **Discovery:** Active Directory enumeration using NetExec.
- **Lateral Movement:** Remote command execution via NetExec; SYSVOL share replication.
- **Collection:** [Not explicitly detailed in text, assumed staging for exfiltration].
- **Exfiltration:** Remote tunneling via VS Code.
- **Impact:** Warlock ransomware encryption.
## Impact Assessment
- **Financial:** High (Ransomware recovery costs and potential extortion).
- **Data Breach:** Compromise of internal SharePoint data and Active Directory credentials.
- **Operational:** Critical (Disruption to water utilities and telecom providers).
- **Reputational:** Significant public impact due to the targeting of government bodies and universities.
## Indicators of Compromise
- **Network:** VS Code tunneling traffic (Defanged: hxxps[://]vscode[.]dev)
- **File:**
- K7RKScan driver (vulnerable driver used for BYOVD)
- NetExec (Open-source pen-testing tool)
- Warlock Ransomware binaries
- **Behavioral:**
- Rapid EDR/AV service termination across multiple hosts.
- Unusual SYSVOL file additions.
- VS Code running as a system service.
## Response Actions
- **Containment:** Isolation of compromised SharePoint servers and domain controllers.
- **Eradication:** Removal of malicious web shells and unauthorized VS Code services; patching of SharePoint instances.
- **Recovery:** Restoration of hosts from backups following the EDR-killer/ransomware event.
## Lessons Learned
- **Key Takeaways:** Zero-day SharePoint vulnerabilities remain a primary target for state-linked actors. The transition from zero-day exploitation to ransomware deployment happens rapidly.
- **Gap Analysis:** Vulnerable drivers (BYOVD) successfully bypassed traditional EDR protections, highlighting a need for driver blocklists and memory integrity protections.
## Recommendations
- **Patch Management:** Immediately apply all Microsoft SharePoint security updates.
- **Hardening:** Implement Windows Defender Application Control (WDAC) to block known vulnerable drivers.
- **Monitoring:** Monitor for unauthorized use of Visual Studio Code tunneling and NetExec activity within the environment.
- **Least Privilege:** Audit SYSVOL permissions and restrict service account privileges.