Warlock Ransomware Exploits Zero‑Day SharePoint Flaws to Hit Water Utility, Telecom Operator and Others
What Happened — The China‑linked Warlock ransomware group leveraged a chain of four SharePoint zero‑day vulnerabilities (CVE‑2025‑49704, CVE‑2025‑49706, CVE‑2025‑53770, CVE‑2025‑53771) to gain initial access to on‑premises SharePoint farms at a water utility, a telecom provider, a regional government body and a university. After establishing footholds, the actors deployed a BYOVD driver (CVE‑2025‑1055) to disable AV/EDR on ~40 hosts, staged the ransomware payload in SYSVOL, and launched Warlock on at least 33 systems.
Why It Matters for Trust & Control Assurance
- Demonstrates how unpatched application vulnerabilities can bypass traditional perimeter defenses, underscoring the need for continuous vulnerability management and evidence of timely patching.
- Shows the value of a control‑assurance program that logs remediation actions, validates patch deployment, and provides auditable proof that critical systems are hardened.
- Highlights the importance of monitoring for abnormal driver loading and AV/EDR disable events as part of an ongoing detection and response control set.
Who Is Affected – Critical infrastructure (water utilities), telecom operators, regional government agencies, and higher‑education institutions that run on‑premises SharePoint deployments.
Recommended Actions
- Immediately verify that all SharePoint servers are patched for the four ToolShell CVEs; apply Microsoft’s out‑of‑band updates where available.
- Deploy a continuous control‑mapping solution to track patch status against the “vulnerability remediation” control objective and generate audit‑ready evidence.
- Enable strict driver‑allow‑list policies and monitor for unsigned or anomalous driver loads; integrate alerts into your SIEM for rapid response.
- Conduct a focused incident‑response tabletop exercise that includes ransomware containment, AV/EDR restoration, and SYSVOL integrity checks.
Source: BleepingComputer
Technical Notes
- Attack vector: exploitation of SharePoint zero‑day vulnerabilities (ToolShell) followed by BYOVD driver abuse (CVE‑2025‑1055) to kill AV/EDR.
- Payload staging in SYSVOL enabled rapid lateral execution via Group Policy.
- Use of VS Code tunneling and NetExec facilitated remote command execution and credential spraying.
Source: same as above