Warlock Ransomware Exploits Unpatched SharePoint Flaws to Target Critical Infrastructure
What Happened — The Warlock ransomware group (aka Longlegs) continues to breach organizations by exploiting unpatched SharePoint vulnerabilities first disclosed in 2025. In the past two months the attackers compromised a water utility, a telecom provider, a regional government body, and a university across Europe, Africa, and Latin America.
Why It Matters for Trust & Control Assurance
- Unpatched SharePoint servers illustrate a gap in vulnerability‑management controls that continuous assurance programs are built to detect and remediate.
- The use of a signed but vulnerable driver to disable security tools shows the need for evidence‑based monitoring of privileged software changes.
- Mapping this exploit to a single control objective (vulnerability management) provides audit‑ready evidence across multiple frameworks (e.g., NIST CSF, ISO 27001).
Who Is Affected – Critical‑infrastructure operators (water utilities), telecom carriers, government agencies, and higher‑education institutions.
Recommended Actions – Conduct a rapid inventory of all SharePoint instances, verify patch levels against the latest Microsoft security bulletins, and capture remediation evidence in a continuous control‑assurance platform. Validate that privileged driver installations are logged and reviewed. Source: https://securityaffairs.com/200304/malware/warlock-ransomware-still-exploits-year-old-sharepoint-flaws-to-hit-critical-infrastructure.html
Technical Notes – Initial access is achieved via exploitation of legacy SharePoint zero‑days (ToolShell chain). Attackers plant a webshell in the LAYOUTS directory, steal ASP.NET machine keys, and use DLL sideloading to run payloads downloaded from legitimate hosting services. A signed driver (K7RKScan) is used to disable security software before ransomware deployment. Source: https://securityaffairs.com/200304/malware/warlock-ransomware-still-exploits-year-old-sharepoint-flaws-to-hit-critical-infrastructure.html