The China-linked ransomware group known as Warlock has been exploiting Microsoft SharePoint vulnerabilities to breach a water utility, a telecom provider, a regional government body, and a university, according to researchers at Symantec and Carbon Black. Over the past two months, the group’s targeting has concentrated on Portuguese- and Spanish-speaking countries across Europe, Africa, and Latin America.

Warlock first surfaced in June 2025 and drew attention a month later after exploiting a chain of SharePoint zero-days known as ToolShell, tracked as CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771. Microsoft later linked ToolShell exploitation to state-backed groups Linen Typhoon and Violet Typhoon, as well as a ransomware actor it tracks as Storm-2603. Symantec identifies the same threat actor as Longlegs and attributes development of the Warlock ransomware to the group.

Rapid defense evasion, fast encryption

In one intrusion that began on July 22, the attacker deployed a tool that disabled protection software on at least 40 hosts within roughly two hours, then launched Warlock ransomware on at least 33 of those systems. After initial access, typically gained by exploiting on-premises SharePoint deployments, the attacker drops a web shell built to work across multiple SharePoint versions.

Researchers observed the AV/EDR-killing tool deployed via a bring your own vulnerable driver (BYOVD) technique using a signed K7RKScan driver vulnerable to CVE-2025-1055. Two days after initial access in the July 22 intrusion, the attacker conducted reconnaissance and deleted apparent staging artifacts.

Living-off-the-land tooling

The ransomware payload was staged in the domain’s SYSVOL share, a method that allows the payload to be pushed network-wide via a logon script or Group Policy object rather than host by host. The attacker also installed Visual Studio Code Insiders as a service to enable remote access through VS Code’s built-in tunneling feature, and used the open-source penetration testing framework NetExec for Active Directory enumeration, credential spraying, and remote command execution.

The final stage of the July intrusion occurred on July 31, with Warlock ransomware executing almost immediately after protection software was disabled on each host. Researchers warn that ToolShell and related SharePoint vulnerabilities remain a viable initial access vector more than a year after they were first exploited. The report includes indicators of compromise covering both files and infrastructure used in the attacks.