A Highly Evasive Ransomware Group Exploits SharePoint Vulnerabilities, Targeting Utilities and Governments Across Europe, Africa, and Latin America
A sophisticated China-linked ransomware group, known as Warlock, has been wreaking havoc on critical infrastructure across multiple continents. Over the past two months, this highly evasive threat actor has successfully breached a water utility, a telecom provider, a regional government body, and a university by exploiting SharePoint vulnerabilities to gain initial access.
Warlock’s modus operandi involves targeting countries where Portuguese or Spanish are spoken, including Europe, Africa, and Latin America. The group emerged in June 2025, quickly gaining notoriety after leveraging zero-day vulnerabilities in Microsoft SharePoint known as ToolShell (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771). By August, Microsoft had already observed state-backed hacking groups, such as Linen Typhoon and Violet Typhoon, using these exploits in their attacks.
Once inside the network, Warlock deploys a web shell designed to function across multiple SharePoint versions. This allows the attackers to gain persistent access and launch further attacks. In one particularly concerning incident, researchers from Symantec and Carbon Black observed that Warlock deployed an EDR (Endpoint Detection and Response) killer tool on at least 40 hosts within two hours of gaining access. The attackers then launched the Warlock ransomware on at least 33 hosts.
The analysis of this attack revealed some disturbing tactics employed by Warlock. For instance, after gaining initial access, the threat actor engaged in reconnaissance activity, deleted staging artifacts, and staged the ransomware payload in the domain’s SYSVOL share – a location that stores public files and is replicated across every domain controller. This method allows the attackers to push the payload out for execution by a logon script or Group Policy object across an entire network at once.
Furthermore, Warlock used Visual Studio Code Insiders’ tunneling capability to connect remotely to compromised machines. The researchers also found that the open-source penetration testing framework NetExec was used for Active Directory enumeration, credential spraying, and remote command execution.
The final stage of the attack occurred on July 31st, after deploying the EDR killer tool, with Warlock ransomware appearing almost as soon as protection was disabled on each host. The researchers warn that ToolShell and other SharePoint vulnerabilities remain viable initial access vectors, more than a year after Warlock first emerged exploiting these flaws.
This incident serves as a stark reminder of the ongoing threat posed by sophisticated ransomware groups like Warlock. Organizations must prioritize patching their SharePoint deployments and implementing robust security measures to prevent such attacks. Additionally, users should be aware of the potential risks associated with using third-party tools, especially those that may have vulnerabilities or be exploited by attackers.
To mitigate this risk, organizations should:
* Regularly update and patch their software, particularly on-premises SharePoint deployments
* Implement robust security measures, including EDR solutions, to detect and prevent attacks
* Conduct thorough vulnerability assessments to identify potential entry points for attackers
By taking proactive steps to secure their networks and systems, organizations can significantly reduce the risk of being targeted by highly evasive threat actors like Warlock.
Source: Bleeping Computer — 2026-10-02