As reported by BleepingComputer, the China-linked Warlock ransomware operation has been systematically targeting critical infrastructure — including a water utility and telecom provider — using a chain of SharePoint zero-day vulnerabilities collectively known as ToolShell. This is not a routine ransomware story; it represents the continued convergence of nation-state capability with financially motivated extortion, and it demands immediate attention from defenders in critical sectors.
Why This Matters
The ToolShell vulnerability chain — CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771 — has become shared infrastructure across multiple Chinese threat actors, including Microsoft-tracked Linen Typhoon, Violet Typhoon, and Storm-2603. Symantec attributes the Warlock payload to the group it tracks as Longlegs. When multiple state-aligned groups operationalize the same exploit chain, it indicates centralized vulnerability research brokered across affiliates — and that means the window between disclosure and mass exploitation is collapsing.
What sets this campaign apart is the targeting profile. Water utilities and telecom providers are lifeline sectors where operational disruption can cascade into public safety consequences. The fact that Warlock chose these verticals — alongside a regional government and university — suggests either strategic intelligence gathering dressed in ransomware cover or a deliberate willingness to accept critical-infrastructure collateral for financial gain.
| CVE | Component | Severity | Status |
|---|---|---|---|
| CVE-2025-49704 | Microsoft SharePoint (ToolShell) | Critical | Patch available |
| CVE-2025-49706 | Microsoft SharePoint (ToolShell) | Critical | Patch available |
| CVE-2025-53770 | Microsoft SharePoint (ToolShell) | Critical | Patch available |
| CVE-2025-53771 | Microsoft SharePoint (ToolShell) | Critical | Patch available |
| CVE-2025-1055 | K7RKScan driver (BYOVD) | High | Driver blocklist update needed |
Attack Chain Highlights
- Initial access: Exploitation of unpatched on-premises SharePoint via ToolShell, followed by persistent multi-version web shell deployment.
- EDR evasion: BYOVD technique leveraging the legitimately signed K7RKScan driver (CVE-2025-1055) to disable endpoint protection across 40+ hosts within two hours.
- Lateral movement: NetExec framework for Active Directory enumeration and credential spraying.
- Remote access: VS Code Insiders installed as a service to abuse its built-in tunneling capability — a legitimate tool increasingly co-opted for C2 channels.
- Payload distribution: Ransomware binary staged in SYSVOL, enabling domain-wide execution via GPO or logon scripts — a technique that converts a single foothold into mass encryption rapidly.
The SYSVOL staging technique is particularly dangerous because it weaponizes the trust model of Active Directory itself. Any domain-joined host pulling policy from a compromised DC executes the payload — no agent deployment required.
Shield53 Recommendations
vscode.dev and global.rel.tunnels.api.visualstudio.com where remote development is not an approved workflow. Monitor for VS Code Insiders installations on production systems.Defenders in critical infrastructure should assume that the ToolShell exploit chain is now commoditized and will continue circulating among financially and geopolitically motivated actors alike. The window for patching is measured in hours, not weeks.