Warlock Ransomware Group Exploits SharePoint Flaws in Global Attacks
A China-linked cybercrime group, tracked as Longlegs (Storm-2603), continues to breach organizations using Warlock ransomware, leveraging unpatched Microsoft SharePoint vulnerabilities and a vulnerable signed driver to disable security tools before encryption. Since June 2025, the group has targeted entities across Europe, Africa, and Latin America, including a water utility, telecommunications provider, regional government body, and university in Portuguese- and Spanish-speaking countries over the past two months.
The attackers exploit on-premises SharePoint Server flaws, including CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771 (collectively known as "ToolShell"), as well as newer vulnerabilities flagged by CISA in July 2026. Early victims spanned the U.S., Brazil, India, Russia, Taiwan, and Japan.
Attack Chain & Tactics
Longlegs deploys a webshell in the SharePoint LAYOUTS directory, stealing ASP.NET machine keys to forge a signed __VIEWSTATE payload, enabling remote code execution (RCE). The group uses DLL sideloading, pulling payloads from legitimate services like catbox[.]moe and wasabisys[.]com, and abuses K7RKScan (CVE-2025-1055), a vulnerable signed driver, to terminate security processes at the kernel level a bring-your-own-vulnerable-driver (BYOVD) technique.
For stealth, the attackers employ living-off-the-land (LotL) tools, including Visual Studio Code’s code-insiders.exe with its tunnel feature, masking malicious traffic as legitimate developer activity. In a July 2026 attack on critical infrastructure, the group:
- July 22: Dropped a webshell (layout2sp.aspx) via PowerShell.
- July 24: Conducted reconnaissance with net user /domain, whoami, and nltest /domain_trusts, then deleted staging files.
- July 27: Used oastify.com (Burp Collaborator) to confirm RCE.
- July 28: Exploited System.Workflow.ComponentModel for deserialization, fetched MSI packages via msiexec, and created a fake SharePoint service account (SPSEPRDSetup) with local admin privileges.
- July 31: Deployed an AV/EDR killer (a.exe) across 40+ hosts, followed by Warlock ransomware (run.exe, rune.exe) and a ransom note (how to restore your files.txt), delivered via SYSVOL share and DFSR replication.
Indicators of Compromise (IoCs)
- Domains: litter[.]catbox[.]moe, xn8xyt-drop[.]s3[.]wasabisys[.]com
- Hashes:
- Warlock ransomware: 116ca4e88a1bcebb6c0da7fb431c8eca7b8ef3f9767194820c56091972ccac2c
- AV/EDR killer: 73c5268256c9da5488cd9e2b79013060ac321c7e54129344dc7b51e268af36ea
- Vulnerable driver (K7RKScan): ae9f7fce57c7b928e659dccf0e00fa79cd9cd61a106f18d4e03f92dc3a03c295
The campaign underscores the persistent risk of unpatched SharePoint servers, with Longlegs demonstrating adaptive tactics to evade detection and maximize impact.
Source: https://cyberpress.org/warlock-ransomware-sharepoint/
Microsoft TPRM report: https://www.rankiteo.com/company/microsoft_sharepoint
"id": "mic1790872213",
"linkid": "microsoft_sharepoint",
"type": "Vulnerability",
"date": "10/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': 'Utilities',
'location': ['Europe', 'Africa', 'Latin America'],
'type': 'Water utility'},
{'industry': 'Telecommunications',
'location': ['Europe', 'Africa', 'Latin America'],
'type': 'Telecommunications provider'},
{'industry': 'Government',
'location': ['Europe', 'Africa', 'Latin America'],
'type': 'Regional government body'},
{'industry': 'Education',
'location': ['Europe', 'Africa', 'Latin America'],
'type': 'University'}],
'attack_vector': ['Exploitation of unpatched SharePoint vulnerabilities',
'DLL sideloading',
'Bring-Your-Own-Vulnerable-Driver (BYOVD)'],
'data_breach': {'data_encryption': True,
'data_exfiltration': True,
'personally_identifiable_information': True,
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['Personally identifiable '
'information',
'System credentials']},
'date_detected': '2025-06-01',
'date_publicly_disclosed': '2026-07-01',
'description': 'A China-linked cybercrime group, tracked as Longlegs '
'(Storm-2603), continues to breach organizations using Warlock '
'ransomware, leveraging unpatched Microsoft SharePoint '
'vulnerabilities and a vulnerable signed driver to disable '
'security tools before encryption. The group has targeted '
'entities across Europe, Africa, and Latin America, including '
'a water utility, telecommunications provider, regional '
'government body, and university in Portuguese- and '
'Spanish-speaking countries.',
'impact': {'brand_reputation_impact': True,
'data_compromised': True,
'identity_theft_risk': True,
'operational_impact': 'Disruption of critical infrastructure '
'services',
'systems_affected': ['SharePoint servers', '40+ hosts']},
'initial_access_broker': {'backdoors_established': ['Webshell in SharePoint '
'LAYOUTS directory'],
'entry_point': 'Exploitation of SharePoint '
'vulnerabilities'},
'investigation_status': 'Ongoing',
'lessons_learned': 'The campaign underscores the persistent risk of unpatched '
'SharePoint servers and the need for adaptive security '
'measures to counter evolving threats.',
'motivation': 'Financial gain',
'post_incident_analysis': {'corrective_actions': ['Patch management for '
'SharePoint',
'Restrict vulnerable driver '
'usage',
'Enhanced monitoring for '
'LotL tools'],
'root_causes': ['Unpatched SharePoint '
'vulnerabilities',
'Abuse of vulnerable signed '
'drivers']},
'ransomware': {'data_encryption': True,
'data_exfiltration': True,
'ransomware_strain': 'Warlock'},
'recommendations': ['Patch SharePoint vulnerabilities immediately',
'Monitor for unusual activity in SharePoint LAYOUTS '
'directory',
'Restrict use of vulnerable signed drivers',
'Enhance detection for living-off-the-land (LotL) tools',
'Implement network segmentation and enhanced monitoring'],
'references': [{'date_accessed': '2026-07-01', 'source': 'CISA'}],
'threat_actor': 'Longlegs (Storm-2603)',
'title': 'Warlock Ransomware Group Exploits SharePoint Flaws in Global '
'Attacks',
'type': 'Ransomware',
'vulnerability_exploited': ['CVE-2025-49704',
'CVE-2025-49706',
'CVE-2025-53770',
'CVE-2025-53771',
'CVE-2025-1055']}