The China-linked ransomware group known as Warlock has targeted a water utility, a telecom provider, a regional government body and a university by exploiting vulnerabilities in on-premises Microsoft SharePoint servers.
Symantec researchers say the group has recently focused on organizations in Portuguese- and Spanish-speaking countries across Europe, Africa and Latin America. Active since June 2025, Warlock has been exploiting a series of SharePoint zero-days known as ToolShell (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770 and CVE-2025-53771).
After gaining access, attackers typically install a web shell that works across different SharePoint versions. In some intrusions, researchers also found an antivirus and endpoint detection and response (AV/EDR) bypass tool using the “bring your own vulnerable driver” (BYOVD) technique. The tool abused a signed K7RKScan driver affected by the CVE-2025-1055 privilege escalation flaw.
In a July attack, the threat actors conducted network reconnaissance and later deployed a tool that disabled security software on at least 40 hosts within two hours. Warlock ransomware was then deployed on at least 33 systems.
The attackers also staged the ransomware in the domain’s SYSVOL share, a location that is automatically replicated to every domain controller and readable domain-wide.
“Staging the payload inside the domain's SYSVOL share, a location that is automatically replicated to every domain controller and readable domain-wide, is a known method of pushing a payload out for execution by a logon script or Group Policy object across an entire network at once, rather than one host at a time,” the report notes.
Researchers also found Visual Studio Code Insiders installed as a service. Its built-in tunneling feature gave the attackers a way to remotely connect to compromised machines. The attackers used an open-source penetration-testing tool called NetExec (nxc.exe) for Active Directory enumeration, credential spraying and remote command execution.
In the final stage, the attackers deployed an AV/EDR-killing tool (a.exe), which likely leveraged a vulnerable driver.
“The Warlock ransomware began appearing almost as soon as protection was disabled on each host. Two binaries, run.exe and rune.exe, together with a ransom note titled "how to restore your files.txt," were recorded on at least 33 hosts across the organization,” Symantec said.