Warlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical Infrastructure
Summary
Warlock ransomware operators continue to exploit unpatched, internet-facing Microsoft SharePoint servers more than a year after the ToolShell vulnerability chain was first disclosed. Symantec tracks the China-nexus group behind Warlock as Longlegs, also known as Storm-2603, and has associated it with older activity clusters including CL-CRI-1040, CamoFei, and ChamelGang.
Recent victims include a water utility, telecommunications provider, regional government organization, and university across Europe, Africa, and Latin America. Warlock attacks have also been observed against organizations in the United States, Brazil, India, Russia, Taiwan, and Japan.
The attackers exploit SharePoint vulnerabilities to deploy a web shell, steal ASP.NET machine keys, and generate signed malicious payloads that execute inside the SharePoint application pool. The intrusion then progresses through reconnaissance, DLL sideloading, payload delivery, persistent remote access, privilege expansion, security-tool disruption, lateral movement, and domain-wide ransomware deployment.
Background
Warlock ransomware emerged in June 2025 and gained attention when Storm-2603 began exploiting the Microsoft SharePoint vulnerability chain known as ToolShell. ToolShell combines authentication-control weaknesses with remote code execution vulnerabilities affecting on-premises SharePoint Server deployments.
Longlegs continues to favor SharePoint vulnerabilities for initial access. The group installs web shells in SharePoint LAYOUTS directories and designs them to operate across different SharePoint versions. These web shells extract ASP.NET machine keys that can be used to sign malicious ViewState payloads.
Once code execution is established, the group uses legitimate utilities and trusted services to reduce detection. Observed techniques include PowerShell, Windows command-line tools, DLL sideloading, MSI installation, NetExec, Visual Studio Code tunnels, public file-hosting services, and vulnerable signed drivers.
In previous attacks, Longlegs used the vulnerable signed K7RKScan driver to terminate protected security processes before deploying ransomware. In the detailed 2026 intrusion, the exact driver used by the AV/EDR-killing tool could not be conclusively identified.
Vulnerability Details
The ToolShell attack chain is associated with four SharePoint vulnerabilities. The original chain combined CVE-2025-49706 and CVE-2025-49704. CVE-2025-53771 and CVE-2025-53770 addressed related weaknesses that could bypass protections introduced for the earlier vulnerabilities.
These vulnerabilities affect on-premises SharePoint Server deployments. SharePoint Online in Microsoft 365 is not affected.
| CVE | Vulnerability | CVSS Score | Affected Products | Impact |
|---|---|---|---|---|
| CVE-2025-49704 | Improper control of code generation | 8.8 | Microsoft SharePoint Server 2016, Microsoft SharePoint Server 2019, and Microsoft SharePoint Server Subscription Edition | Remote code execution by an authenticated attacker |
| CVE-2025-49706 | Improper authentication | 6.5 | Spoofing and authentication-control bypass | |
| CVE-2025-53770 | Deserialization of untrusted data | 9.8 | Unauthenticated remote code execution | |
| CVE-2025-53771 | Path traversal and improper authentication | 6.5 | Spoofing and security-feature bypass |
Attack Methodology
Initial Access Through SharePoint
Longlegs identifies exposed, unpatched SharePoint servers and exploits the ToolShell vulnerability chain. The attacker then installs a web shell in a SharePoint LAYOUTS directory, allowing commands to execute through the w3wp.exe IIS worker process.
Machine-Key Theft and Signed Payload Execution
The web shell extracts the SharePoint farm's ASP.NET validation and decryption keys. Using this key material, the attacker creates a malicious __VIEWSTATE payload with a signature that SharePoint accepts as valid.
When the forged payload is processed, a .NET deserialization gadget executes attacker-controlled code inside the SharePoint application pool.
Discovery and Domain Enumeration
The attackers use standard Windows utilities to identify:
- The current user and privilege context
- Domain users and administrative accounts
- Active Directory domain trusts
- Reachable computers and services
- Potential paths for lateral movement
Observed commands included whoami, net user /domain, and nltest /domain_trusts.
DLL Sideloading and Payload Delivery
Longlegs uses legitimate executables to sideload malicious DLLs. Observed executable and DLL pairs included doexe.exe with doexeloc.dll, as well as ssvagent.exe and logger.exe with malicious DLL components.
Additional MSI packages were downloaded from legitimate public hosting services, including catbox.moe and wasabisys.com. Using legitimate hosting infrastructure helps malicious traffic blend with expected web activity.
Privilege Expansion and Persistent Remote Access
The attackers added a domain account named SPSEPRDSetup to local Administrators groups on multiple systems. The SharePoint-style name may have been selected to make the account appear legitimate.
Visual Studio Code Insiders was also installed as a tunneling service. Because the executable is signed by Microsoft and communicates through Microsoft infrastructure, the resulting traffic may resemble legitimate developer or administrator activity.
Defense Evasion and Ransomware Deployment
Before deploying Warlock, the attackers distributed a tool intended to disable antivirus and EDR protection. The tool was observed on at least 40 systems within approximately two hours.
Warlock payloads named run.exe and rune.exe were then staged in the domain's SYSVOL share. Because SYSVOL is replicated across domain controllers, normal Distributed File System Replication activity delivered the ransomware files throughout the domain.
Warlock was observed on at least 33 systems shortly after security protection was disabled.
Indicators of Compromise (IOCs)
File, Account, and Network Indicators
| Indicator | Type | Description |
|---|---|---|
layout2sp.aspx |
File name | SharePoint web shell |
ssvagent.exe |
File name | Executable used for DLL sideloading |
logger.exe |
File name | Executable used for DLL sideloading |
doexe.exe |
File name | Executable used to load a malicious DLL |
doexeloc.dll |
File name | Malicious sideloaded DLL |
gsdll64.dll.tmp |
File name | Malicious DLL component |
a.exe |
File name | AV/EDR-killing tool |
run.exe |
File name | Warlock ransomware payload |
rune.exe |
File name | Warlock ransomware payload |
how to restore your files.txt |
File name | Warlock ransom note |
SPSEPRDSetup |
Account | Account added to local Administrators groups |
litter[.]catbox[.]moe |
Domain | Follow-on payload hosting |
xn8xyt-drop[.]s3[.]wasabisys[.]com |
Domain | Follow-on MSI payload hosting |
s3[.]wasabisys[.]com/fortifs/vamd64.msi |
URL path | Observed MSI download location |
SHA-256 Indicators
| SHA-256 | Classification |
|---|---|
116ca4e88a1bcebb6c0da7fb431c8eca7b8ef3f9767194820c56091972ccac2c |
Warlock ransomware |
155fb1cbdaea12c83ba92d18c88cf38bbc42bb684f913ca0bc26fcf115426a55 |
Warlock ransomware |
6d07f1232dc59b84038fd0b2e75fdd3d5b825882bb0dba9e6724b7b0823fa3ad |
Warlock ransomware |
8b58f7811a2a2f2a5024220490473774f02759dd2dd904b5b9fabfbaae37125f |
Warlock ransomware |
8ce8d8270ee9de02644530b8dd7fa78973b4a3b80f121e2c5f45ae68cce196f9 |
Warlock ransomware |
73c5268256c9da5488cd9e2b79013060ac321c7e54129344dc7b51e268af36ea |
AV/EDR-killing tool |
ae9f7fce57c7b928e659dccf0e00fa79cd9cd61a106f18d4e03f92dc3a03c295 |
Vulnerable driver |
1edb2c0b537cd95bbd5fc16321b4c38a6adf325ccc7b588ad6acc980b0463b60 |
Malicious DLL |
206f27ae820783b7755bca89f83a0fe096dbb510018dd65b63fc80bd20c03261 |
Malicious DLL |
27b7591cf9e1283010ca98fa5dbe970a73fee0d8cde277639924c144718db7c0 |
Malicious DLL |
c46825fcc0d1bf7a8b192facb176d6bf916c9dccfd6fa994be691e3b0e585f4e |
Malicious DLL |
e14240bac8277b0f6dd4d29ab5da20d246bcccae647e5fe8d19cdae7fe471b20 |
Malicious DLL |
fb3846c9ac53d1b841ada3a6b1091153fea41a169cb44fe0084097d1f4d45984 |
Malicious DLL |
Domains belonging to public hosting or development services may also support legitimate activity. Treat matches as investigation leads and correlate them with file, process, identity, SharePoint, and network telemetry.
MITRE ATT&CK Mapping
| Tactic | Technique | Technique ID | Observed Use |
|---|---|---|---|
| Initial Access | Exploit Public-Facing Application | T1190 | Exploitation of internet-facing on-premises SharePoint servers. |
| Persistence | Server Software Component: Web Shell | T1505.003 | Deployment of an ASPX web shell in SharePoint LAYOUTS directories. |
| Execution | PowerShell | T1059.001 | PowerShell was used to write payloads, load .NET assemblies, and download files. |
| Execution | Windows Command Shell | T1059.003 | Command Prompt and batch-style instructions supported execution and staging. |
| Defense Evasion | Hijack Execution Flow: DLL Side-Loading | T1574.002 | Trusted executables were used to load malicious DLLs. |
| Discovery | Domain Account Discovery | T1087.002 | The attackers used domain-user enumeration commands. |
| Discovery | Permission Groups Discovery: Local Groups | T1069.001 | Local administrative access and group membership were manipulated and reviewed. |
| Discovery | Domain Trust Discovery | T1482 | nltest /domain_trusts was used to enumerate trust relationships. |
| Command and Control | Ingress Tool Transfer | T1105 | MSI packages and additional payloads were downloaded from public hosting services. |
| Command and Control | Remote Access Software | T1219 | Visual Studio Code tunneling was installed for covert remote access. |
| Defense Evasion | Impair Defenses: Disable or Modify Tools | T1562.001 | A vulnerable-driver-based tool was used to terminate antivirus and EDR processes. |
| Impact | Data Encrypted for Impact | T1486 | Warlock encrypted systems after endpoint protection was disabled. |
Visual Attack Flow
-
1
Internet-Facing SharePoint Server
Longlegs identifies an exposed and unpatched on-premises SharePoint deployment.
-
2
ToolShell Exploitation
The SharePoint authentication and remote code execution chain provides initial access.
-
3
Web-Shell Deployment
An ASPX web shell is placed in a SharePoint LAYOUTS directory.
-
4
ASP.NET Machine-Key Theft
The web shell extracts validation and decryption keys from the SharePoint farm.
-
5
Signed ViewState Execution
A forged machine-key-signed ViewState payload triggers code execution through deserialization.
-
6
Discovery and Lateral Movement
The attackers enumerate the domain, sideload DLLs, create administrative access, and move to additional systems.
-
7
Security Protection Disabled
An AV/EDR-killing tool is distributed across the environment.
-
8
SYSVOL Ransomware Distribution
Warlock payloads are staged in SYSVOL and propagated through normal domain replication.
-
9
Domain-Wide Encryption
Warlock executes across compromised systems and encrypts organizational data.
Mitigation
Treat an exposed and unpatched on-premises SharePoint server as potentially compromised, because applying updates does not remove web shells, invalidate stolen ASP.NET machine keys, or reverse attacker-created access.
- Apply the latest cumulative SharePoint security updates to every server in the farm. The July 2025 minimum baselines are KB5002768 for Subscription Edition, KB5002754 and KB5002753 for SharePoint Server 2019, and KB5002760 and KB5002759 for SharePoint Server 2016. Use later cumulative security updates when available, and install both language-dependent and language-independent packages where required.
- After patching, rotate the SharePoint farm's ASP.NET validation and decryption keys, then restart IIS on every SharePoint server so stolen keys can no longer be used to sign malicious ViewState payloads.
- Enable SharePoint AMSI integration in Full Mode and verify that protection is active across the farm.
- Remove direct internet exposure from SharePoint. Where external access is required, place it behind an authenticated application gateway or reverse proxy and restrict access to approved users and networks.
- Search SharePoint LAYOUTS directories for unexpected ASPX files, especially
layout2sp.aspx, and investigatew3wp.exelaunching PowerShell, command shells, MSI installers, or unfamiliar executables. - Hunt for the
SPSEPRDSetupaccount, unauthorized additions to local Administrators groups, Visual Studio Code tunnel services, malicious DLL-sideloading pairs, and the confirmed file hashes and domains listed in the IOC section. - Inspect SYSVOL for
run.exe,rune.exe, unexpected executables, or staging directories, and review domain-controller replication activity for signs of ransomware distribution. - Isolate and rebuild compromised SharePoint servers when machine-key theft, web-shell activity, or administrative compromise is confirmed. Reset affected credentials and investigate lateral movement before returning the farm to service.
Instantly Fix Risks with Saner Patch Management
Saner patch management is a continuous, automated, and integrated software that instantly fixes risks exploited in the wild. The software supports major operating systems like Windows, Linux, and macOS, as well as 550+ third-party applications.
It also allows you to set up a safe testing area to test patches before deploying them in a primary production environment. Saner patch management additionally supports a patch rollback feature in case of patch failure or a system malfunction.
Experience the fastest and most accurate patching software here.




