Warlock Ransomware Attacks Target Water and Telecom Sectors
The China-linked Warlock ransomware group has targeted critical infrastructure sectors, including a water utility and a telecom provider, by exploiting vulnerabilities in Microsoft SharePoint deployments.

Warlock Ransomware Targets Critical Infrastructure
The China-linked ransomware group known as Warlock has expanded its targeting to critical infrastructure and public sector organizations. Recent threat intelligence reports highlight that the gang has focused on a water utility, a telecom provider, a regional government body, and a university. According to BleepingComputer, these attacks leverage vulnerabilities in on-premises SharePoint deployments to gain initial access. Further details are available from BleepingComputer in the original source material.
Over the past two months, the threat actor's campaign has primarily concentrated on Portuguese- and Spanish-speaking countries across Europe, Africa, and Latin America. The ransomware gang originally emerged in June 2025 and quickly gained notoriety a month later after exploiting a chain of zero-day vulnerabilities in Microsoft SharePoint.
Exploitation of SharePoint and the ToolShell Flaws
The threat group gained significant attention after exploiting a chain of zero-day vulnerabilities in Microsoft SharePoint known as ToolShell, which includes CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771. By August, Microsoft observed state-backed hacking groups Linen Typhoon and Violet Typhoon utilizing ToolShell exploits, alongside a ransomware threat actor tracked as Storm-2603.
Cybersecurity company Symantec identifies the same underlying actor as Longlegs, attributing the development of the Warlock ransomware specifically to this group. Upon breaching a network by exploiting SharePoint, the attacker typically drops a versatile web shell designed to function seamlessly across multiple versions of the platform.
Intrusion Tactics and Security Software Disabling
Detailed analysis of an intrusion that began on July 22 illustrates the speed and methodology of the threat actor. Within about two hours, the attacker deployed a tool that disabled protection software on at least 40 hosts. Following this, the ransomware payload was launched on at least 33 hosts.
Symantec and Carbon Black researchers note that in attacks attributed to Longlegs, an AV/EDR-killing tool was deployed utilizing the bring your own vulnerable driver technique. This process involved a signed K7RKScan driver vulnerable to CVE-2025-1055, effectively neutralizing endpoint protection mechanisms before final payload execution.
Reconnaissance and Payload Staging via SYSVOL
During the July 22 incident, investigators observed that two days after gaining initial access, the threat actor engaged in active reconnaissance and deleted suspected staging artifacts. The ransomware payload itself was strategically staged within the domain’s SYSVOL share, a repository storing public files replicated across every domain controller.
Security analysts point out that this is a recognized method for pushing a payload out for execution via a logon script or Group Policy object across an entire network simultaneously, rather than infecting hosts one by one.
Remote Access and Final Ransomware Deployment
To maintain remote access, the main executable file for Visual Studio Code Insiders was installed as a service, leveraging VS Code's built-in tunneling capability to connect remotely to compromised machines. Additionally, researchers identified the open-source penetration testing framework NetExec on one of the systems, assisting the attacker with Active Directory enumeration, credential spraying, and remote command execution.
The final stage of the sequence occurred on July 31st. Following the deployment of the AV/EDR killer, Warlock ransomware appeared almost instantaneously as protection was disabled on each host. Security researchers warn that ToolShell and other SharePoint vulnerabilities remain viable initial access vectors long after the initial discovery of these flaws.
Sources
- BleepingComputerWarlock ransomware breach SharePoint in water, telecom operator attacks
Continue chronologically





