SecPod

Learn Search

Search across all Learn content

← Back to Security Research
Warlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical Infrastructure

Warlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical Infrastructure

Oct 6, 2026By Pranav M Rao6 min read

Summary

Warlock ransomware operators continue to exploit unpatched, internet-facing Microsoft SharePoint servers more than a year after the ToolShell vulnerability chain was first disclosed. Symantec tracks the China-nexus group behind Warlock as Longlegs, also known as Storm-2603, and has associated it with older activity clusters including CL-CRI-1040, CamoFei, and ChamelGang.

Recent victims include a water utility, telecommunications provider, regional government organization, and university across Europe, Africa, and Latin America. Warlock attacks have also been observed against organizations in the United States, Brazil, India, Russia, Taiwan, and Japan.

The attackers exploit SharePoint vulnerabilities to deploy a web shell, steal ASP.NET machine keys, and generate signed malicious payloads that execute inside the SharePoint application pool. The intrusion then progresses through reconnaissance, DLL sideloading, payload delivery, persistent remote access, privilege expansion, security-tool disruption, lateral movement, and domain-wide ransomware deployment.

Background

Warlock ransomware emerged in June 2025 and gained attention when Storm-2603 began exploiting the Microsoft SharePoint vulnerability chain known as ToolShell. ToolShell combines authentication-control weaknesses with remote code execution vulnerabilities affecting on-premises SharePoint Server deployments.

Longlegs continues to favor SharePoint vulnerabilities for initial access. The group installs web shells in SharePoint LAYOUTS directories and designs them to operate across different SharePoint versions. These web shells extract ASP.NET machine keys that can be used to sign malicious ViewState payloads.

Once code execution is established, the group uses legitimate utilities and trusted services to reduce detection. Observed techniques include PowerShell, Windows command-line tools, DLL sideloading, MSI installation, NetExec, Visual Studio Code tunnels, public file-hosting services, and vulnerable signed drivers.

In previous attacks, Longlegs used the vulnerable signed K7RKScan driver to terminate protected security processes before deploying ransomware. In the detailed 2026 intrusion, the exact driver used by the AV/EDR-killing tool could not be conclusively identified.

Vulnerability Details

The ToolShell attack chain is associated with four SharePoint vulnerabilities. The original chain combined CVE-2025-49706 and CVE-2025-49704. CVE-2025-53771 and CVE-2025-53770 addressed related weaknesses that could bypass protections introduced for the earlier vulnerabilities.

These vulnerabilities affect on-premises SharePoint Server deployments. SharePoint Online in Microsoft 365 is not affected.

CVE Vulnerability CVSS Score Affected Products Impact
CVE-2025-49704 Improper control of code generation 8.8 Microsoft SharePoint Server 2016, Microsoft SharePoint Server 2019, and Microsoft SharePoint Server Subscription Edition Remote code execution by an authenticated attacker
CVE-2025-49706 Improper authentication 6.5 Spoofing and authentication-control bypass
CVE-2025-53770 Deserialization of untrusted data 9.8 Unauthenticated remote code execution
CVE-2025-53771 Path traversal and improper authentication 6.5 Spoofing and security-feature bypass

Attack Methodology

Initial Access Through SharePoint

Longlegs identifies exposed, unpatched SharePoint servers and exploits the ToolShell vulnerability chain. The attacker then installs a web shell in a SharePoint LAYOUTS directory, allowing commands to execute through the w3wp.exe IIS worker process.

Machine-Key Theft and Signed Payload Execution

The web shell extracts the SharePoint farm's ASP.NET validation and decryption keys. Using this key material, the attacker creates a malicious __VIEWSTATE payload with a signature that SharePoint accepts as valid.

When the forged payload is processed, a .NET deserialization gadget executes attacker-controlled code inside the SharePoint application pool.

Discovery and Domain Enumeration

The attackers use standard Windows utilities to identify:

  • The current user and privilege context
  • Domain users and administrative accounts
  • Active Directory domain trusts
  • Reachable computers and services
  • Potential paths for lateral movement

Observed commands included whoami, net user /domain, and nltest /domain_trusts.

DLL Sideloading and Payload Delivery

Longlegs uses legitimate executables to sideload malicious DLLs. Observed executable and DLL pairs included doexe.exe with doexeloc.dll, as well as ssvagent.exe and logger.exe with malicious DLL components.

Additional MSI packages were downloaded from legitimate public hosting services, including catbox.moe and wasabisys.com. Using legitimate hosting infrastructure helps malicious traffic blend with expected web activity.

Privilege Expansion and Persistent Remote Access

The attackers added a domain account named SPSEPRDSetup to local Administrators groups on multiple systems. The SharePoint-style name may have been selected to make the account appear legitimate.

Visual Studio Code Insiders was also installed as a tunneling service. Because the executable is signed by Microsoft and communicates through Microsoft infrastructure, the resulting traffic may resemble legitimate developer or administrator activity.

Defense Evasion and Ransomware Deployment

Before deploying Warlock, the attackers distributed a tool intended to disable antivirus and EDR protection. The tool was observed on at least 40 systems within approximately two hours.

Warlock payloads named run.exe and rune.exe were then staged in the domain's SYSVOL share. Because SYSVOL is replicated across domain controllers, normal Distributed File System Replication activity delivered the ransomware files throughout the domain.

Warlock was observed on at least 33 systems shortly after security protection was disabled.

Indicators of Compromise (IOCs)

File, Account, and Network Indicators

Indicator Type Description
layout2sp.aspx File name SharePoint web shell
ssvagent.exe File name Executable used for DLL sideloading
logger.exe File name Executable used for DLL sideloading
doexe.exe File name Executable used to load a malicious DLL
doexeloc.dll File name Malicious sideloaded DLL
gsdll64.dll.tmp File name Malicious DLL component
a.exe File name AV/EDR-killing tool
run.exe File name Warlock ransomware payload
rune.exe File name Warlock ransomware payload
how to restore your files.txt File name Warlock ransom note
SPSEPRDSetup Account Account added to local Administrators groups
litter[.]catbox[.]moe Domain Follow-on payload hosting
xn8xyt-drop[.]s3[.]wasabisys[.]com Domain Follow-on MSI payload hosting
s3[.]wasabisys[.]com/fortifs/vamd64.msi URL path Observed MSI download location

SHA-256 Indicators

SHA-256 Classification
116ca4e88a1bcebb6c0da7fb431c8eca7b8ef3f9767194820c56091972ccac2c Warlock ransomware
155fb1cbdaea12c83ba92d18c88cf38bbc42bb684f913ca0bc26fcf115426a55 Warlock ransomware
6d07f1232dc59b84038fd0b2e75fdd3d5b825882bb0dba9e6724b7b0823fa3ad Warlock ransomware
8b58f7811a2a2f2a5024220490473774f02759dd2dd904b5b9fabfbaae37125f Warlock ransomware
8ce8d8270ee9de02644530b8dd7fa78973b4a3b80f121e2c5f45ae68cce196f9 Warlock ransomware
73c5268256c9da5488cd9e2b79013060ac321c7e54129344dc7b51e268af36ea AV/EDR-killing tool
ae9f7fce57c7b928e659dccf0e00fa79cd9cd61a106f18d4e03f92dc3a03c295 Vulnerable driver
1edb2c0b537cd95bbd5fc16321b4c38a6adf325ccc7b588ad6acc980b0463b60 Malicious DLL
206f27ae820783b7755bca89f83a0fe096dbb510018dd65b63fc80bd20c03261 Malicious DLL
27b7591cf9e1283010ca98fa5dbe970a73fee0d8cde277639924c144718db7c0 Malicious DLL
c46825fcc0d1bf7a8b192facb176d6bf916c9dccfd6fa994be691e3b0e585f4e Malicious DLL
e14240bac8277b0f6dd4d29ab5da20d246bcccae647e5fe8d19cdae7fe471b20 Malicious DLL
fb3846c9ac53d1b841ada3a6b1091153fea41a169cb44fe0084097d1f4d45984 Malicious DLL

Domains belonging to public hosting or development services may also support legitimate activity. Treat matches as investigation leads and correlate them with file, process, identity, SharePoint, and network telemetry.

MITRE ATT&CK Mapping

Tactic Technique Technique ID Observed Use
Initial Access Exploit Public-Facing Application T1190 Exploitation of internet-facing on-premises SharePoint servers.
Persistence Server Software Component: Web Shell T1505.003 Deployment of an ASPX web shell in SharePoint LAYOUTS directories.
Execution PowerShell T1059.001 PowerShell was used to write payloads, load .NET assemblies, and download files.
Execution Windows Command Shell T1059.003 Command Prompt and batch-style instructions supported execution and staging.
Defense Evasion Hijack Execution Flow: DLL Side-Loading T1574.002 Trusted executables were used to load malicious DLLs.
Discovery Domain Account Discovery T1087.002 The attackers used domain-user enumeration commands.
Discovery Permission Groups Discovery: Local Groups T1069.001 Local administrative access and group membership were manipulated and reviewed.
Discovery Domain Trust Discovery T1482 nltest /domain_trusts was used to enumerate trust relationships.
Command and Control Ingress Tool Transfer T1105 MSI packages and additional payloads were downloaded from public hosting services.
Command and Control Remote Access Software T1219 Visual Studio Code tunneling was installed for covert remote access.
Defense Evasion Impair Defenses: Disable or Modify Tools T1562.001 A vulnerable-driver-based tool was used to terminate antivirus and EDR processes.
Impact Data Encrypted for Impact T1486 Warlock encrypted systems after endpoint protection was disabled.

Visual Attack Flow

  1. 1
    Internet-Facing SharePoint Server

    Longlegs identifies an exposed and unpatched on-premises SharePoint deployment.

  2. 2
    ToolShell Exploitation

    The SharePoint authentication and remote code execution chain provides initial access.

  3. 3
    Web-Shell Deployment

    An ASPX web shell is placed in a SharePoint LAYOUTS directory.

  4. 4
    ASP.NET Machine-Key Theft

    The web shell extracts validation and decryption keys from the SharePoint farm.

  5. 5
    Signed ViewState Execution

    A forged machine-key-signed ViewState payload triggers code execution through deserialization.

  6. 6
    Discovery and Lateral Movement

    The attackers enumerate the domain, sideload DLLs, create administrative access, and move to additional systems.

  7. 7
    Security Protection Disabled

    An AV/EDR-killing tool is distributed across the environment.

  8. 8
    SYSVOL Ransomware Distribution

    Warlock payloads are staged in SYSVOL and propagated through normal domain replication.

  9. 9
    Domain-Wide Encryption

    Warlock executes across compromised systems and encrypts organizational data.

Mitigation

Treat an exposed and unpatched on-premises SharePoint server as potentially compromised, because applying updates does not remove web shells, invalidate stolen ASP.NET machine keys, or reverse attacker-created access.

  • Apply the latest cumulative SharePoint security updates to every server in the farm. The July 2025 minimum baselines are KB5002768 for Subscription Edition, KB5002754 and KB5002753 for SharePoint Server 2019, and KB5002760 and KB5002759 for SharePoint Server 2016. Use later cumulative security updates when available, and install both language-dependent and language-independent packages where required.
  • After patching, rotate the SharePoint farm's ASP.NET validation and decryption keys, then restart IIS on every SharePoint server so stolen keys can no longer be used to sign malicious ViewState payloads.
  • Enable SharePoint AMSI integration in Full Mode and verify that protection is active across the farm.
  • Remove direct internet exposure from SharePoint. Where external access is required, place it behind an authenticated application gateway or reverse proxy and restrict access to approved users and networks.
  • Search SharePoint LAYOUTS directories for unexpected ASPX files, especially layout2sp.aspx, and investigate w3wp.exe launching PowerShell, command shells, MSI installers, or unfamiliar executables.
  • Hunt for the SPSEPRDSetup account, unauthorized additions to local Administrators groups, Visual Studio Code tunnel services, malicious DLL-sideloading pairs, and the confirmed file hashes and domains listed in the IOC section.
  • Inspect SYSVOL for run.exe, rune.exe, unexpected executables, or staging directories, and review domain-controller replication activity for signs of ransomware distribution.
  • Isolate and rebuild compromised SharePoint servers when machine-key theft, web-shell activity, or administrative compromise is confirmed. Reset affected credentials and investigate lateral movement before returning the farm to service.

Instantly Fix Risks with Saner Patch Management

Saner patch management is a continuous, automated, and integrated software that instantly fixes risks exploited in the wild. The software supports major operating systems like Windows, Linux, and macOS, as well as 550+ third-party applications.

It also allows you to set up a safe testing area to test patches before deploying them in a primary production environment. Saner patch management additionally supports a patch rollback feature in case of patch failure or a system malfunction.

Experience the fastest and most accurate patching software here.

Featured Posts

Open CVE-2026-90970: GitLab Strengthens AI Gateway Security Following Critical Vulnerability
CVE-2026-90970: GitLab Strengthens AI Gateway Security Following Critical Vulnerability

CVE Research

CVE-2026-90970: GitLab Strengthens AI Gateway Security Following Critical Vulnerability

Oct 5, 2026

Open Open Door: Critical FortiMail Zero-Day Exploited to Write Arbitrary Files
Open Door: Critical FortiMail Zero-Day Exploited to Write Arbitrary Files

CVE Research

Open Door: Critical FortiMail Zero-Day Exploited to Write Arbitrary Files

Fortinet has disclosed CVE-2026-104286, a critical unauthenticated path traversal and NULL-byte handling vulnerability in FortiMail that allows arbitrary file writes via crafted HTTP or HTTPS requests. The issue is reported as exploited in the wild and is listed in the CISA KEV catalog. This article covers impact, affected versions, workarounds, fixed-build guidance, and indicators of compromise.

Oct 5, 2026

Open WHIPSHOT and SLAPSHOT: Citrix NetScaler Zero-Days Exploited to Plant Root Web Shells and Internal Tunnels
WHIPSHOT and SLAPSHOT: Citrix NetScaler Zero-Days Exploited to Plant Root Web Shells and Internal Tunnels

CVE Research

WHIPSHOT and SLAPSHOT: Citrix NetScaler Zero-Days Exploited to Plant Root Web Shells and Internal Tunnels

Oct 1, 2026

Open OpenSSL’s DTLS State Handling Error Opens the Door to Heap Data Exposure
OpenSSL’s DTLS State Handling Error Opens the Door to Heap Data Exposure

CVE Research

OpenSSL’s DTLS State Handling Error Opens the Door to Heap Data Exposure

Oct 1, 2026