Warlock ransomware breach SharePoint in water, telecom operator attacks
Warlock ransomware exploited SharePoint ToolShell flaws to hit a water utility, telecom, government body, and university.
The China-linked Warlock ransomware group, tracked by Symantec as Longlegs and related to Microsoft's Storm-2603, attacked a water utility, a telecom provider, a regional government body, and a university. Initial access came from on-premises Microsoft SharePoint ToolShell flaws CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771, followed by a web shell. In a July 22 intrusion, the actor used a BYOVD EDR killer leveraging a signed K7RKScan driver (CVE-2025-1055) on at least 40 hosts, staged Warlock in SYSVOL, abused Visual Studio Code tunneling and NetExec, and encrypted at least 33 hosts on July 31.
- Warlock hit water, telecom, government, and a university via SharePoint ToolShell.
- Initial access used CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771.
- A BYOVD tool using vulnerable K7RKScan driver CVE-2025-1055 hit 40 hosts.
- Attackers staged Warlock in SYSVOL and used VS Code tunnels plus NetExec.
- Ransomware encrypted at least 33 hosts right after endpoint protection was disabled.
Vulnerabilities mentionedAll →
- CVE-2025-10555.6<1%A vulnerability in the K7RKScan.sys driver, part of the K7 Security Anti-Malware suite, allows a local low-privilege user to send crafted IOCTL requests to…published
- CVE-2025-497048.8100%Authenticated Code Injection RCE in Microsoft SharePoint
Full article515 words · extracted from bleepingcomputer.com · click to collapse

The China-linked ransomware group Warlock targeted a water utility, a telecom provider, a regional government body, and a university by exploiting SharePoint vulnerabilities to gain initial access.
Over the past two months, the threat actor appears to have focused on countries speaking Portuguese and Spanish across Europe, Africa, and Latin America.
The gang emerged in June 2025 and gained notoriety a month later after exploiting a chain of zero-day vulnerabilities in Microsoft SharePoint known as ToolShell (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771).
By August, Microsoft observed state-backed hacking groups Linen Typhoon and Violet Typhoon using ToolShell exploits in attacks, along with a ransomware threat actor the company tracks as Storm-2603.
EDR killer deployed to 40 hosts
Cybersecurity company Symantec identifies the same actor as Longlegs and attributes the development of the Warlock ransomware to the group.
According to the researchers, in one intrusion that started on July 22, the threat actor deployed a tool that disabled protection software on “at least 40 hosts within about two hours.” The attacker then launched Warlock ransomware on at least 33 hosts.
After gaining access, typically by exploiting vulnerabilities in on-premises SharePoint deployments, the attacker drops a web shell designed to function across multiple SharePoint versions.
Symantec and Carbon Black researchers say that in some attacks attributed to Longlegs, an AV/EDR-killing tool was deployed via the bring your own vulnerable driver (BYOVD) technique using a signed K7RKScan driver vulnerable to CVE-2025-1055.
Analysis of the intrusion on July 22 revealed that two days after gaining initial access, the threat actor engaged in reconnaissance activity and deleted what seemed like staging artifacts.
Using VS Code's tunneling capability
The ransomware payload was staged in the domain’s SYSVOL share, a location that stores public files and is replicated across every domain controller.
This is “a known method of pushing a payload out for execution by a logon script or Group Policy object across an entire network at once, rather than one host at a time,” the researchers say.
During the attack, the main executable file for Visual Studio Code Insiders was installed as a service to enable connecting remotely to compromised machines using VS Code's built-in tunneling capability.
On one of the systems, the researchers found the open-source penetration testing framework NetExec, which helped the attacker with Active Directory enumeration, credential spraying, and remote command execution.
The final stage of the attack occurred on July 31st, after deploying the AV/EDR killer, with Warlock ransomware “appearing almost as soon as protection was disabled on each host.”
The researchers warn that ToolShell and other SharePoint vulnerabilities remain viable initial access vectors, more than a year after Warlock first emerged exploiting SharePoint flaws.
The report from the Symantec and Carbon Black threat hunters includes a set of indicators of compromise for files and infrastructure used in the attacks.
Build your security blueprint for AI-powered attacks
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.