Skip to content
Rush Commerce
Software & Dev3 min read

Warlock ransomware rides year-old SharePoint ToolShell bugs

Symantec says Warlock ransomware used 2025 SharePoint ToolShell flaws, a VS Code tunnel, and SYSVOL to hit 33+ hosts in two hours. Patch and rotate keys.

The Warlock ransomware gang is still getting in through SharePoint ToolShell, a set of bugs Microsoft patched in July 2025. Symantec's threat hunters say Warlock hit at least four organizations in the past two months: a water utility, a telecom provider, a regional government body, and a university. In one intrusion, the ransomware reached 33+ hosts within two hours. If you run SharePoint on your own server and skipped last year's emergency patch, this is about you.

What actually happened

The Symantec and Carbon Black Threat Hunter Team report, published October 1, describes the chain step by step. The detailed intrusion ran from July 22 to 31, 2026:

  • Initial access through ToolShell: CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771.
  • Web shells dropped into SharePoint's LAYOUTS directory to steal the farm's ASP.NET machine keys. With those keys, attackers sign their own payloads and run code at will.
  • Security tools disabled with a vulnerable K7 driver (CVE-2025-1055). This is "bring your own vulnerable driver."
  • Remote access through Visual Studio Code's built-in tunnel, installed as a service. It looks like a developer tool, because it is one.
  • Payloads staged on catbox.moe and Wasabi cloud storage.
  • Ransomware pushed through the domain's SYSVOL share, which replicates to every domain controller and machine.

The victims are in Portuguese- and Spanish-speaking countries in Europe, Africa, and Latin America. The Hacker News has a summary.

Why the SharePoint ToolShell patch still matters for your business

A year-old bug is now the cheapest way into a network. Attackers don't need a zero-day when you didn't install last year's fix.

And patching alone is not enough. If the machine keys were stolen before you patched, the attacker can still forge requests. We said this about another SharePoint bug, and it applies again.

Our checklist for any on-prem SharePoint:

  1. Confirm the July 2025 ToolShell updates are installed. Then confirm every update since.
  2. Rotate the ASP.NET machine keys and restart IIS. Do this even if you think you patched on time.
  3. Look for unknown .aspx files in the LAYOUTS directory.
  4. Hunt for VS Code tunnels you didn't set up: code tunnel services, or code-insiders.exe on a server.
  5. Block unsigned and known-vulnerable drivers. Turn on Microsoft's vulnerable driver blocklist.
  6. Watch SYSVOL for new executables. Nothing should drop an .exe there without a change ticket.

Better question: does this file server need to be on-prem at all? For most small teams, SharePoint Online removes the patch job completely.

Key takeaways

  • Symantec ties Warlock ransomware to four victims in two months, all entered via 2025 SharePoint ToolShell flaws
  • Attackers stole ASP.NET machine keys, so patching without key rotation leaves the door open
  • They disabled security tools with a vulnerable K7 driver and used a VS Code tunnel for remote access
  • Ransomware spread through SYSVOL to 33+ hosts in two hours
  • Patch, rotate machine keys, hunt for web shells and rogue tunnels, and enable the driver blocklist

Old servers are where the ransomware starts. We audit what's on-prem, patch or migrate it, and leave you with a named owner for every system. See what we do, or tell us what you're still running in the closet.

Sources: Symantec Threat Hunter Team, The Hacker News.

  • #warlock
  • #ransomware
  • #sharepoint
  • #toolshell
  • #byovd
TR

Tommy Rush — Founder, Rush Commerce

Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More

Get The Rush Report weekly — one email, zero fluff.