Microsoft: Warlock Attackers Abuse Vulnerable Driver to Disable Security Tools Before Ransomware Deployment

Microsoft: Warlock Attackers Abuse Vulnerable Driver to Disable Security Tools Before Ransomware Deployment

Warlock Ransomware Group Exploits SharePoint Flaws in Global Attacks

A China-linked cybercrime group, tracked as Longlegs (Storm-2603), continues to breach organizations using Warlock ransomware, leveraging unpatched Microsoft SharePoint vulnerabilities and a vulnerable signed driver to disable security tools before encryption. Since June 2025, the group has targeted entities across Europe, Africa, and Latin America, including a water utility, telecommunications provider, regional government body, and university in Portuguese- and Spanish-speaking countries over the past two months.

The attackers exploit on-premises SharePoint Server flaws, including CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771 (collectively known as "ToolShell"), as well as newer vulnerabilities flagged by CISA in July 2026. Early victims spanned the U.S., Brazil, India, Russia, Taiwan, and Japan.

Attack Chain & Tactics
Longlegs deploys a webshell in the SharePoint LAYOUTS directory, stealing ASP.NET machine keys to forge a signed __VIEWSTATE payload, enabling remote code execution (RCE). The group uses DLL sideloading, pulling payloads from legitimate services like catbox[.]moe and wasabisys[.]com, and abuses K7RKScan (CVE-2025-1055), a vulnerable signed driver, to terminate security processes at the kernel level a bring-your-own-vulnerable-driver (BYOVD) technique.

For stealth, the attackers employ living-off-the-land (LotL) tools, including Visual Studio Code’s code-insiders.exe with its tunnel feature, masking malicious traffic as legitimate developer activity. In a July 2026 attack on critical infrastructure, the group:

  • July 22: Dropped a webshell (layout2sp.aspx) via PowerShell.
  • July 24: Conducted reconnaissance with net user /domain, whoami, and nltest /domain_trusts, then deleted staging files.
  • July 27: Used oastify.com (Burp Collaborator) to confirm RCE.
  • July 28: Exploited System.Workflow.ComponentModel for deserialization, fetched MSI packages via msiexec, and created a fake SharePoint service account (SPSEPRDSetup) with local admin privileges.
  • July 31: Deployed an AV/EDR killer (a.exe) across 40+ hosts, followed by Warlock ransomware (run.exe, rune.exe) and a ransom note (how to restore your files.txt), delivered via SYSVOL share and DFSR replication.

Indicators of Compromise (IoCs)

  • Domains: litter[.]catbox[.]moe, xn8xyt-drop[.]s3[.]wasabisys[.]com
  • Hashes:
    • Warlock ransomware: 116ca4e88a1bcebb6c0da7fb431c8eca7b8ef3f9767194820c56091972ccac2c
    • AV/EDR killer: 73c5268256c9da5488cd9e2b79013060ac321c7e54129344dc7b51e268af36ea
    • Vulnerable driver (K7RKScan): ae9f7fce57c7b928e659dccf0e00fa79cd9cd61a106f18d4e03f92dc3a03c295

The campaign underscores the persistent risk of unpatched SharePoint servers, with Longlegs demonstrating adaptive tactics to evade detection and maximize impact.

Source: https://cyberpress.org/warlock-ransomware-sharepoint/

Microsoft TPRM report: https://www.rankiteo.com/company/microsoft_sharepoint

"id": "mic1790872213",
"linkid": "microsoft_sharepoint",
"type": "Vulnerability",
"date": "10/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': 'Utilities',
                        'location': ['Europe', 'Africa', 'Latin America'],
                        'type': 'Water utility'},
                       {'industry': 'Telecommunications',
                        'location': ['Europe', 'Africa', 'Latin America'],
                        'type': 'Telecommunications provider'},
                       {'industry': 'Government',
                        'location': ['Europe', 'Africa', 'Latin America'],
                        'type': 'Regional government body'},
                       {'industry': 'Education',
                        'location': ['Europe', 'Africa', 'Latin America'],
                        'type': 'University'}],
 'attack_vector': ['Exploitation of unpatched SharePoint vulnerabilities',
                   'DLL sideloading',
                   'Bring-Your-Own-Vulnerable-Driver (BYOVD)'],
 'data_breach': {'data_encryption': True,
                 'data_exfiltration': True,
                 'personally_identifiable_information': True,
                 'sensitivity_of_data': 'High',
                 'type_of_data_compromised': ['Personally identifiable '
                                              'information',
                                              'System credentials']},
 'date_detected': '2025-06-01',
 'date_publicly_disclosed': '2026-07-01',
 'description': 'A China-linked cybercrime group, tracked as Longlegs '
                '(Storm-2603), continues to breach organizations using Warlock '
                'ransomware, leveraging unpatched Microsoft SharePoint '
                'vulnerabilities and a vulnerable signed driver to disable '
                'security tools before encryption. The group has targeted '
                'entities across Europe, Africa, and Latin America, including '
                'a water utility, telecommunications provider, regional '
                'government body, and university in Portuguese- and '
                'Spanish-speaking countries.',
 'impact': {'brand_reputation_impact': True,
            'data_compromised': True,
            'identity_theft_risk': True,
            'operational_impact': 'Disruption of critical infrastructure '
                                  'services',
            'systems_affected': ['SharePoint servers', '40+ hosts']},
 'initial_access_broker': {'backdoors_established': ['Webshell in SharePoint '
                                                     'LAYOUTS directory'],
                           'entry_point': 'Exploitation of SharePoint '
                                          'vulnerabilities'},
 'investigation_status': 'Ongoing',
 'lessons_learned': 'The campaign underscores the persistent risk of unpatched '
                    'SharePoint servers and the need for adaptive security '
                    'measures to counter evolving threats.',
 'motivation': 'Financial gain',
 'post_incident_analysis': {'corrective_actions': ['Patch management for '
                                                   'SharePoint',
                                                   'Restrict vulnerable driver '
                                                   'usage',
                                                   'Enhanced monitoring for '
                                                   'LotL tools'],
                            'root_causes': ['Unpatched SharePoint '
                                            'vulnerabilities',
                                            'Abuse of vulnerable signed '
                                            'drivers']},
 'ransomware': {'data_encryption': True,
                'data_exfiltration': True,
                'ransomware_strain': 'Warlock'},
 'recommendations': ['Patch SharePoint vulnerabilities immediately',
                     'Monitor for unusual activity in SharePoint LAYOUTS '
                     'directory',
                     'Restrict use of vulnerable signed drivers',
                     'Enhance detection for living-off-the-land (LotL) tools',
                     'Implement network segmentation and enhanced monitoring'],
 'references': [{'date_accessed': '2026-07-01', 'source': 'CISA'}],
 'threat_actor': 'Longlegs (Storm-2603)',
 'title': 'Warlock Ransomware Group Exploits SharePoint Flaws in Global '
          'Attacks',
 'type': 'Ransomware',
 'vulnerability_exploited': ['CVE-2025-49704',
                             'CVE-2025-49706',
                             'CVE-2025-53770',
                             'CVE-2025-53771',
                             'CVE-2025-1055']}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.