As reported by BleepingComputer, the China-linked Warlock ransomware operation has been systematically targeting critical infrastructure — including a water utility and telecom provider — using a chain of SharePoint zero-day vulnerabilities collectively known as ToolShell. This is not a routine ransomware story; it represents the continued convergence of nation-state capability with financially motivated extortion, and it demands immediate attention from defenders in critical sectors.

Ransomware Alert: As reported by BleepingComputer, the China-linked Warlock ransomware operation has been systematically targeting critical infrastructure — including a water utility and telecom provider — using a chain of SharePoint zero-day vulnerabilities collectively known as ToolShell.

Why This Matters

The ToolShell vulnerability chain — CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771 — has become shared infrastructure across multiple Chinese threat actors, including Microsoft-tracked Linen Typhoon, Violet Typhoon, and Storm-2603. Symantec attributes the Warlock payload to the group it tracks as Longlegs. When multiple state-aligned groups operationalize the same exploit chain, it indicates centralized vulnerability research brokered across affiliates — and that means the window between disclosure and mass exploitation is collapsing.

What sets this campaign apart is the targeting profile. Water utilities and telecom providers are lifeline sectors where operational disruption can cascade into public safety consequences. The fact that Warlock chose these verticals — alongside a regional government and university — suggests either strategic intelligence gathering dressed in ransomware cover or a deliberate willingness to accept critical-infrastructure collateral for financial gain.

CVEComponentSeverityStatus
CVE-2025-49704Microsoft SharePoint (ToolShell)CriticalPatch available
CVE-2025-49706Microsoft SharePoint (ToolShell)CriticalPatch available
CVE-2025-53770Microsoft SharePoint (ToolShell)CriticalPatch available
CVE-2025-53771Microsoft SharePoint (ToolShell)CriticalPatch available
CVE-2025-1055K7RKScan driver (BYOVD)HighDriver blocklist update needed

Attack Chain Highlights

  • Initial access: Exploitation of unpatched on-premises SharePoint via ToolShell, followed by persistent multi-version web shell deployment.
  • EDR evasion: BYOVD technique leveraging the legitimately signed K7RKScan driver (CVE-2025-1055) to disable endpoint protection across 40+ hosts within two hours.
  • Lateral movement: NetExec framework for Active Directory enumeration and credential spraying.
  • Remote access: VS Code Insiders installed as a service to abuse its built-in tunneling capability — a legitimate tool increasingly co-opted for C2 channels.
  • Payload distribution: Ransomware binary staged in SYSVOL, enabling domain-wide execution via GPO or logon scripts — a technique that converts a single foothold into mass encryption rapidly.

The SYSVOL staging technique is particularly dangerous because it weaponizes the trust model of Active Directory itself. Any domain-joined host pulling policy from a compromised DC executes the payload — no agent deployment required.

Shield53 Recommendations

Shield53 Recommendations
Patch SharePoint immediately. All on-premises SharePoint servers must be updated to versions addressing CVE-2025-49704, -49706, -53770, and -53771. Internet-facing SharePoint instances are the highest priority. If patching cannot be completed within 24 hours, restrict external access until remediation is complete.
Update driver blocklists. Ensure your EDR solution's vulnerable driver blocklist includes the K7RKScan driver. Microsoft's recommended driver block rules in Windows Defender Application Control should be enforced via GPO. Any endpoint still permitting signed-but-vulnerable driver loads is a soft target for BYOVD.
Monitor SYSVOL for anomalies. Deploy file integrity monitoring on SYSVOL shares. Alert on any new executable files, scripts, or unexpected modifications. This should be treated as a high-fidelity detection — legitimate SYSVOL changes are rare and well-controlled.
Restrict VS Code tunneling. Block outbound traffic to vscode.dev and global.rel.tunnels.api.visualstudio.com where remote development is not an approved workflow. Monitor for VS Code Insiders installations on production systems.
Hunt for web shells. All on-premises SharePoint deployments should be scanned for unexpected .aspx or .ashx files, particularly in custom or temp directories. The multi-version web shell described in this campaign was designed for persistence across SharePoint updates.
Review GPO and logon script hygiene. Inventory all Group Policy Objects and logon scripts. Any unauthorized additions or modifications should trigger incident response procedures.

Defenders in critical infrastructure should assume that the ToolShell exploit chain is now commoditized and will continue circulating among financially and geopolitically motivated actors alike. The window for patching is measured in hours, not weeks.