As reported by The Hacker News, the suspected China-linked threat cluster known as Warlock (also tracked as Gold Salem, Longlegs, and Storm-2603) continues to weaponize Microsoft SharePoint Server vulnerabilities against critical infrastructure, government, and education targets across Portuguese- and Spanish-speaking nations. The campaign's speed and operational discipline — pushing EDR-disabling tooling to 40 hosts within two hours — deserves more attention than the headline suggests.
The Real Story: ASP.NET Machine Key Theft as a Trust-Breaking Primitive
The most technically significant detail buried in Symantec's reporting is the abuse of ASP.NET machine keys harvested from compromised SharePoint farms. Once an attacker drops a web shell and extracts the farm's machine key, they can forge cryptographically signed payloads that execute inside the SharePoint application pool as trusted code. This effectively bypasses any application-layer authentication or authorization control because the payload carries a valid signature the server itself issued.
This is not a novel technique in isolation — ASP.NET ViewState deserialization attacks have been documented for over a decade — but its weaponization through SharePoint specifically is notable. SharePoint farms are frequently deployed on-premises at large government and infrastructure organizations that have slower patch cycles, making them durable staging grounds for long-term operations.
CVE-2025-1055: Shared BYOVD Driver Amplifies Impact
Warlock's use of the vulnerable K7RKScan.sys driver (CVE-2025-1055) in a bring-your-own-vulnerable-driver (BYOVD) attack to disable endpoint protections is a notable escalation. This same driver was previously exploited by DragonForce ransomware operators, suggesting either shared infrastructure, a common supplier, or convergent tooling selection across distinct criminal ecosystems. The reuse of a single vulnerable driver across multiple ransomware campaigns reinforces the need for blocklisting known-abused drivers organization-wide — not just the ones targeting your current threat landscape.
| Identifier | Type | Severity | Affected Component | Patch/Mitigation Status |
|---|---|---|---|---|
| CVE-2025-1055 | Privilege Escalation / BYOVD | High | K7RKScan.sys (K7 Computing driver) | Driver blocklisting required; vendor patch available |
| "ToolShell" SharePoint Flaws | Remote Code Execution | Critical | Microsoft SharePoint Server (on-premises, multiple versions) | Microsoft security updates available; verify farm patch level |
Why This Campaign Pattern Matters
Warlock's operational tempo — from initial SharePoint access to mass EDR disabling and SYSVOL-delivered ransomware staging — compresses what should be a multi-day incident into hours. By staging payloads in SYSVOL, they weaponize legitimate Active Directory replication as a deployment mechanism, turning the domain's own infrastructure against the defender. This is particularly dangerous because:
The combination of SharePoint key theft, BYOVD EDR disabling, and SYSVOL-based propagation represents a kill chain that can neutralize an entire domain's security posture before most SOCs even receive a first alert.
Shield53 Recommendations
Immediate Actions
- Audit SharePoint Server patch levels immediately. Inventory all on-premises SharePoint farms and verify they are running the latest cumulative updates. Pay particular attention to any server exposed to the internet.
- Rotate ASP.NET machine keys. If any SharePoint farm has been exposed to untrusted networks or shows signs of compromise, rotate all machine keys and ViewState signing keys. Treat existing keys as potentially compromised.
- Deploy Microsoft Vulnerable Driver Blocklist. Ensure the latest Windows HVCI/driver blocklist is enforced across all endpoints, including legacy systems. Verify K7RKScan.sys and other known-abused drivers are explicitly blocked.
- Monitor SYSVOL for unexpected content. Deploy file integrity monitoring on SYSVOL shares and alert on any new executable, DLL, or script that does not originate from Group Policy management processes.
- Restrict outbound traffic to file-sharing services. Block or proxy connections to catbox.moe, wasabisys.com, and similar consumer cloud storage endpoints from server subnets where SharePoint and domain controllers reside.
Strategic Hardening
- Segment SharePoint from domain infrastructure. SharePoint servers should not have line-of-sight to domain controllers beyond what is strictly required for service operation. Limit SYSVOL access patterns.
- Implement EDR tamper protection. Modern EDR solutions support tamper protection that resists BYOVD attacks at the kernel level. Verify this is enabled and tested against known driver-based kill techniques.
- Establish web shell detection baselines. Deploy dedicated IIS/SharePoint web shell detection — monitor for new ASPX/ASHX files in virtual directories, unexpected application pool recycles, and anomalous PowerShell child processes spawning from w3wp.exe.
Warlock's continued success with this playbook — despite the ToolShell vulnerabilities being publicly known since mid-2025 — tells us that on-premises SharePoint remains one of the most under-patched, over-exposed assets in enterprise environments. Until defenders treat SharePoint farms with the same urgency as internet-facing VPN appliances and Exchange servers, threat actors like Warlock will keep finding the door open.