Warlock Ransomware Gang Weaponizes Unpatched SharePoint Servers
A ransomware operation tracked as Warlock — also linked to the Gold Salem, Longlegs, and Storm-2603 clusters — is still actively exploiting Microsoft SharePoint vulnerabilities to break into networks, strip out security tooling, and detonate ransomware at scale. Researchers assess the group has ties to China-nexus activity.
What happened
Over a recent two-month stretch, the group compromised at least four organizations, including two critical infrastructure operators (a water utility and a telecommunications provider), a regional government body, and a university. Victims were concentrated in Portuguese- and Spanish-speaking countries across Europe, Africa, and Latin America.
The crew's primary entry point remains on-premises SharePoint Server deployments vulnerable to the "ToolShell" exploit chain that first surfaced in mid-2025, alongside other unpatched SharePoint flaws. After gaining a foothold, the attackers drop web shells built to work across multiple SharePoint versions. Those web shells harvest the server farm's ASP.NET machine keys, which the attackers then use to forge a validly signed payload and execute code directly inside the SharePoint application pool.
From there, the group leans heavily on "living-off-the-land" tradecraft: abusing legitimate remote-access features such as Visual Studio Code's built-in tunneling to maintain hands-on-keyboard access, and pulling down follow-on payloads from legitimate cloud file-sharing services to avoid tripping network defenses. To clear the way for ransomware, the attackers deploy a Bring-Your-Own-Vulnerable-Driver (BYOVD) technique — in this case abusing a flawed, legitimately signed driver (tracked as CVE-2025-1055) that has also been used by DragonForce ransomware operators to kill endpoint security products.
In one confirmed intrusion against a critical infrastructure operator, the attackers used this driver to disable security software on more than 40 hosts over roughly two months, then staged the ransomware payload inside the compromised domain's SYSVOL share — letting normal domain replication silently push it out to at least 33 machines before detonation.
Why it matters
More than a year after SharePoint's ToolShell vulnerabilities first made headlines, they remain a reliable initial-access route for ransomware crews — proof that patch cycles for on-premises collaboration platforms are still lagging well behind active exploitation. The group's preference for legitimate tooling (VS Code tunnels, signed-but-vulnerable drivers, mainstream cloud storage) is a deliberate strategy to blend in with normal administrator activity and delay detection until ransomware is already staged domain-wide.
What to do
- Patch SharePoint Server now. Confirm all on-premises SharePoint instances are current against the ToolShell exploit chain and any related CVEs; internet-facing, unpatched servers should be treated as compromised until proven otherwise.
- Hunt for machine-key theft and forged payloads. Review SharePoint application pool activity and rotate ASP.NET machine keys if any sign of web shell activity is found.
- Block known-vulnerable drivers. Add BYOVD indicators — including the driver behind CVE-2025-1055 — to your driver block list (e.g., via Microsoft's vulnerable driver blocklist or equivalent EDR controls).
- Monitor SYSVOL for unexpected payloads. Domain replication shares are rarely inspected for malware; alert on new executables or scripts staged there.
- Watch for unsanctioned remote-access tunnels. Flag outbound connections from developer tools such as VS Code's tunnel feature on servers that have no business running them.
- Restrict uploads to consumer cloud storage from server infrastructure, since attackers are using mainstream file-sharing services to host payloads undetected.
