Warlock ransomware breach SharePoint in water, telecom operator attacks

Warlock Ransomware Gang Exploits SharePoint Vulnerabilities, Targeting Water Utility and Telecom Provider in Coordinated Attacks

A sophisticated ransomware group, linked to China, has been wreaking havoc on organizations across Europe, Africa, and Latin America over the past two months. The Warlock gang has exploited vulnerabilities in Microsoft SharePoint to gain initial access, leaving a trail of compromised systems and encrypted data in its wake.

The attackers have focused their efforts on countries where Portuguese and Spanish are spoken, targeting a water utility, a telecom provider, a regional government body, and a university. By exploiting the ToolShell vulnerability (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771), the gang has gained access to these organizations’ networks, using it as a springboard for further attacks.

According to cybersecurity company Symantec, the Warlock ransomware was developed by the same group attributed to Longlegs. Researchers have observed that in one intrusion, the threat actor deployed an EDR (Endpoint Detection and Response) killer tool, disabling protection software on at least 40 hosts within a matter of hours. This allowed the attackers to launch the Warlock ransomware on at least 33 hosts.

The gang’s modus operandi involves exploiting vulnerabilities in on-premises SharePoint deployments, dropping a web shell that functions across multiple SharePoint versions. Once inside, the attackers use various tools and techniques to move laterally within the network, including using Visual Studio Code’s tunneling capability to remotely connect to compromised machines.

Symantec researchers have also discovered that the attackers used an open-source penetration testing framework, NetExec, to aid in Active Directory enumeration, credential spraying, and remote command execution. The final stage of the attack saw the deployment of the AV/EDR killer, allowing the Warlock ransomware to encrypt data on each host almost immediately.

The fact that ToolShell and other SharePoint vulnerabilities remain viable initial access vectors is a worrying development. Despite being exploited over a year ago by Warlock, these flaws still pose a significant threat to organizations worldwide.

Organizations must take immediate action to protect themselves against such attacks. This includes ensuring that all SharePoint deployments are up-to-date with the latest security patches and monitoring for suspicious activity within their networks. By staying vigilant and proactive in their defense strategies, organizations can minimize the risk of falling victim to the Warlock ransomware gang’s coordinated attacks.

Practically speaking, this means implementing robust vulnerability management practices, conducting regular penetration testing, and ensuring that all endpoints are properly configured with up-to-date security software. It also highlights the importance of staying informed about emerging threats and vulnerabilities, and being prepared to adapt defenses accordingly. By doing so, organizations can stay one step ahead of sophisticated attackers like Warlock.


Source: Bleeping Computer — 2026-10-02