Warlock Ransomware Strikes Water Utility and Telecom Operator via SharePoint Zero‑Days
What Happened – The China‑nexus “Longlegs” group deployed Warlock ransomware against a water‑utility and a telecommunications provider in Portuguese‑ and Spanish‑speaking regions. Attackers leveraged a chain of Microsoft SharePoint Server zero‑day exploits (CVE‑2025‑49704, CVE‑2025‑49706, CVE‑2025‑53770, CVE‑2025‑53771) to gain initial access, disabled security software on ~40 hosts, and then propagated ransomware through the domain’s SYSVOL share to at least 33 machines.
Why It Matters for Trust & Control Assurance
- Demonstrates the need for continuous monitoring of privileged share points and rapid detection of exploit activity – a core incident‑response control.
- Highlights the importance of maintaining auditable evidence of ransomware containment and recovery steps to satisfy regulators and auditors.
- Aligns with the Control Mapping capability, which helps organizations map incident‑response controls to multiple frameworks and produce defensible audit artifacts.
Who Is Affected – Critical‑infrastructure operators in the utilities and telecommunications sectors (energy/utilities, telecom).
Recommended Actions
- Verify that all on‑premises SharePoint deployments are patched against the disclosed CVEs; apply mitigations where patches are unavailable.
- Strengthen endpoint detection and response (EDR) to flag driver‑based security‑software disable attempts.
- Update ransomware incident‑response playbooks to include SYSVOL‑based propagation detection and evidence‑collection steps.
- Capture and retain logs from SharePoint, domain controllers, and endpoint agents as continuous control‑assurance evidence.
Technical Notes
- Attack vector: Exploitation of SharePoint Server zero‑day vulnerabilities (ToolShell chain).
- Tools used: Signed driver K7RKScan to disable AV, Visual Studio Code tunneling for covert access, webshells dropped in SharePoint LAYOUTS directory.
- Impact: Ransomware deployed on 33+ hosts, security software disabled on ~40 hosts, likely service disruption for the affected utilities.
Source: Broadcom Symantec Blog – Warlock Ransomware Targets Critical Infrastructure