A sophisticated ransomware group, identified by cybersecurity researchers as Warlock and also known by aliases such as Longlegs and Storm-2603, has been actively exploiting vulnerabilities in Microsoft SharePoint to gain initial access to critical infrastructure. Recent investigations reveal a targeted campaign over the past two months, focusing on organizations in Portuguese and Spanish-speaking countries across Europe, Africa, and Latin America. The group’s modus operandi involves leveraging a chain of zero-day vulnerabilities in Microsoft SharePoint, collectively known as ToolShell, to infiltrate networks and deploy their destructive Warlock ransomware.
The emergence of the Warlock group in June 2025 marked a significant escalation in cyber threats, with their capabilities becoming more widely recognized by July of the same year. This notoriety was largely driven by their successful exploitation of the ToolShell vulnerability set, which includes CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771. These vulnerabilities provided attackers with the ability to execute arbitrary code, allowing them to bypass security measures and establish a foothold within targeted systems. By August, Microsoft had observed not only Warlock but also state-backed hacking groups Linen Typhoon and Violet Typhoon utilizing these same ToolShell exploits, indicating a broader exploitation of these critical weaknesses by various threat actors.
Chronology of Attacks and Exploitation
The Warlock group’s campaign appears to have intensified throughout the latter half of 2025. A particularly illustrative intrusion, detailed by cybersecurity firm Symantec, began on July 22, 2025. Within approximately two hours of gaining initial access, the attackers deployed a potent tool designed to disable endpoint detection and response (EDR) and antivirus software on at least 40 hosts. This aggressive disabling of security defenses paved the way for the subsequent deployment of the Warlock ransomware itself, which was reportedly launched on at least 33 compromised hosts.
The initial vector for these attacks consistently involved exploiting vulnerabilities within on-premises SharePoint deployments. Once access was secured, the threat actors would deploy a web shell, a piece of code that allows attackers to communicate with and control compromised systems remotely. This web shell was designed to be versatile, functioning across multiple versions of SharePoint, thus increasing its effectiveness and the potential reach of the attack.
Two days after the initial breach on July 22, the threat actor meticulously engaged in reconnaissance activities. This phase is critical for understanding the network architecture, identifying high-value targets, and locating sensitive data. During this period, researchers also observed the deletion of what appeared to be staging artifacts, suggesting an effort to remove evidence of their preparatory steps and obfuscate their presence.
Advanced Tactics: EDR Disruption and VS Code Tunneling
A key element of Warlock’s disruptive strategy is its ability to neutralize security software. Symantec and Carbon Black researchers have documented instances where an "EDR killer" tool was deployed using the "bring your own vulnerable driver" (BYOVD) technique. This sophisticated method leverages a legitimate, but vulnerable, signed driver—in this case, a K7RKScan driver susceptible to CVE-2025-1055—to elevate privileges and disable security controls. By exploiting a trusted component, the attackers could bypass many of the protective layers designed to prevent such malicious actions.
The ransomware payload, once prepared, was strategically placed in the domain’s SYSVOL share. This is a critical network location that stores public files and is replicated across all domain controllers within a Windows domain. Researchers highlight this as a "known method of pushing a payload out for execution by a logon script or Group Policy object across an entire network at once, rather than one host at a time." This approach allows for rapid and widespread encryption of files, maximizing the impact of the ransomware attack and increasing the pressure on victims to pay a ransom.
Further enhancing their operational capabilities, the attackers installed the main executable file for Visual Studio Code Insiders as a service on compromised systems. This allowed them to establish remote connections to the compromised machines using VS Code’s built-in tunneling feature. This capability provides a stealthy and encrypted channel for remote command execution and data exfiltration, making their activities harder to detect.
During their intrusions, the threat actors were also observed using the open-source penetration testing framework NetExec. This powerful tool facilitated various malicious activities, including Active Directory enumeration (mapping out the network structure and user accounts), credential spraying (attempting to log in with common passwords), and remote command execution. The combination of NetExec and VS Code tunneling provided the Warlock group with a comprehensive toolkit for lateral movement and control within the compromised networks.

The final stage of the attack unfolded on July 31st, following the deployment of the EDR killer. The Warlock ransomware was observed to initiate its encryption process "almost as soon as protection was disabled on each host." This rapid deployment underscores the attackers’ efficiency and their objective of minimizing the window of opportunity for defenders to react.
Targeted Sectors and Geographical Focus
The Warlock group’s targeting of a water utility, a telecom provider, a regional government body, and a university demonstrates a clear intent to disrupt critical services and potentially impact public safety and infrastructure. These sectors are particularly attractive to ransomware groups due to the high impact of their disruption and the potential for significant financial gain through ransom payments.
The observed focus on countries speaking Portuguese and Spanish is a notable characteristic of this campaign. This suggests a strategic selection of targets, potentially based on language proficiency of the threat actors, regional cyber defense capabilities, or specific geopolitical motivations. The geographical spread across Europe, Africa, and Latin America indicates a global reach and a willingness to exploit vulnerabilities wherever they are found within these linguistic and regional clusters.
Broader Implications and Expert Analysis
The continued viability of ToolShell and other SharePoint vulnerabilities as initial access vectors, more than a year after their initial exploitation by Warlock, highlights a persistent gap in cybersecurity patching and remediation efforts. Organizations relying on on-premises SharePoint deployments remain at significant risk if they have not applied the necessary security updates or implemented compensating controls.
"The successful exploitation of SharePoint vulnerabilities by groups like Warlock serves as a stark reminder of the persistent threats facing organizations that fail to maintain robust patch management programs," stated a cybersecurity analyst who preferred to remain anonymous due to ongoing threat intelligence work. "These zero-day exploits, once discovered and weaponized, can remain effective for extended periods, especially against organizations with legacy systems or slow patching cycles."
The deployment of advanced techniques such as BYOVD and the use of tools like NetExec signify a growing level of technical sophistication within ransomware operations. These tactics are not exclusive to state-sponsored actors and are increasingly being adopted by financially motivated cybercriminal groups, blurring the lines between cyber espionage and cybercrime.
The inclusion of a detailed set of indicators of compromise (IOCs) in the report by Symantec and Carbon Black is crucial for enabling other security teams to detect and defend against similar attacks. These IOCs, which include file hashes, IP addresses, and domain names associated with the Warlock group’s infrastructure, provide actionable intelligence for threat hunting and incident response.
Microsoft, while not issuing a direct statement on Warlock’s activities in this specific report, has previously acknowledged the ToolShell vulnerabilities and released security advisories urging customers to apply relevant updates. The company’s ongoing efforts to track and attribute cyber threats, including state-backed actors and ransomware groups, are vital in understanding the evolving threat landscape.
The Warlock ransomware group’s campaign underscores the critical need for organizations to prioritize their cybersecurity posture, particularly concerning widely used collaboration platforms like SharePoint. Regular vulnerability assessments, prompt patching, robust endpoint security solutions, and comprehensive network monitoring are essential defenses against such persistent and evolving threats. The potential for these attacks to disrupt critical services, impact national security, and cause significant economic damage necessitates a proactive and vigilant approach to cybersecurity. The continued exploitation of these vulnerabilities suggests that the threat landscape will remain challenging, with attackers constantly seeking new ways to bypass defenses and achieve their objectives.







