Skip to main content
The Wire
CyberNews by Zentrya One
critical CVE-2025-49704 & CVE-2025-53770 Vulnerabilities

Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware

Warlock ransomware attackers exploit Microsoft SharePoint vulnerabilities to gain initial access, disable security tools and distribute ransomware across critical infrastructure networks.

The threat actor behind Warlock ransomware is continuing to exploit vulnerabilities in internet-facing Microsoft SharePoint servers, targeting critical infrastructure, government and education organizations.

According to Symantec and Carbon Black researchers, the group—tracked as Longlegs, and also associated with names including Storm-2603 and Gold Salem—attacked at least four organizations during the past two months. Victims included a water utility, telecommunications provider, regional government body and university across Portuguese- and Spanish-speaking countries in Europe, Africa and Latin America.

SharePoint Remains the Initial Access Point

Warlock gained prominence in 2025 after exploiting the Microsoft SharePoint vulnerabilities collectively known as ToolShell.

The original chain involved vulnerabilities including:

CVE Role
CVE-2025-49704 Remote Code Execution
CVE-2025-49706 Authentication/Spoofing weakness
CVE-2025-53770 Related SharePoint RCE
CVE-2025-53771 Related SharePoint vulnerability

These vulnerabilities affect on-premises SharePoint Server, not SharePoint Online in Microsoft 365. Microsoft previously warned that unpatched internet-facing SharePoint servers would continue to attract exploitation.

Symantec says Warlock's more recent intrusions appear to involve exploitation of multiple SharePoint vulnerabilities, potentially including both older and newer flaws.

From SharePoint to Ransomware

After gaining access, the attackers deploy web shells and attempt to obtain the SharePoint farm's ASP.NET machine keys. Those keys can then be abused to create validly signed payloads and execute code inside the SharePoint application pool.

The broader attack sequence looks like:

Vulnerable SharePoint → Web Shell → Machine Key Theft → Code Execution → Network Discovery → Security Tool Disablement → Lateral Movement → Warlock Ransomware

Attackers have also used legitimate services and living-off-the-land techniques to reduce their visibility.

Security Tools Disabled on 40 Hosts

In one attack against a critical infrastructure operator, the attackers distributed a tool designed to disable security software to at least 40 systems in roughly two hours.

Warlock ransomware was subsequently deployed to at least 33 hosts. The attackers placed the ransomware inside the organization's SYSVOL share, allowing normal Active Directory domain replication to help distribute the payload across systems.

The group has also used the Bring Your Own Vulnerable Driver (BYOVD) technique.

Researchers observed exploitation of the legitimate but vulnerable K7RKScan.sys driver, associated with CVE-2025-1055, to terminate security products.

Legitimate Tools Help Attackers Stay Hidden

Warlock operators have incorporated several legitimate tools and services into their attacks, including:

  • Visual Studio Code tunnels for remote access
  • Velociraptor for command-and-control activity
  • Cloud storage and file-sharing services for payload delivery
  • DLL sideloading for malicious code execution
  • Windows command-line and other living-off-the-land utilities
  • SYSVOL and domain replication for ransomware distribution

Microsoft previously observed Storm-2603 using Mimikatz against LSASS, PsExec, WMI and Group Policy Objects during SharePoint-based ransomware intrusions.

What Organizations Should Do

Organizations operating on-premises SharePoint should prioritize:

  • Applying all current Microsoft SharePoint security updates.
  • Removing unnecessary internet exposure.
  • Hunting for suspicious .aspx web shells.
  • Reviewing SharePoint and IIS logs for exploitation attempts.
  • Monitoring for unexpected ASP.NET machine-key access.
  • Detecting suspicious VS Code tunnel activity.
  • Blocking known vulnerable drivers.
  • Monitoring attempts to disable EDR or antivirus products.
  • Reviewing SYSVOL and Group Policy for unauthorized modifications.
  • Isolating systems immediately if ransomware preparation activity is detected.

Because attackers may establish persistence after initial exploitation, simply patching SharePoint may not be sufficient if the server was already compromised. Microsoft has previously documented scheduled tasks, IIS manipulation and additional persistence mechanisms following SharePoint exploitation.

Security Takeaway

The latest Warlock activity demonstrates that unpatched on-premises SharePoint servers remain a valuable entry point for ransomware operators, even more than a year after the original ToolShell exploitation wave.

The most concerning progression is:

SharePoint Exploit → Security Tools Disabled → Domain-Wide Distribution → Warlock Ransomware

Organizations should therefore treat exposed SharePoint vulnerabilities as potential entry points to a broader Active Directory compromise rather than simply as isolated web-server issues.

Filed by Zentrya One Desk · CyberNews desk  ·  Follow Zentrya One on LinkedIn

Related reporting

The Daily Brief

Stay informed. Stay prepared. Stay one step ahead.

One brief each morning: the advisories that matter, the noise removed.

Double opt-in. One-click unsubscribe in every email. We never sell addresses.