Warlock ransomware rides year-old SharePoint ToolShell bugs
Symantec says Warlock ransomware used 2025 SharePoint ToolShell flaws, a VS Code tunnel, and SYSVOL to hit 33+ hosts in two hours. Patch and rotate keys.
The Warlock ransomware gang is still getting in through SharePoint ToolShell, a set of bugs Microsoft patched in July 2025. Symantec's threat hunters say Warlock hit at least four organizations in the past two months: a water utility, a telecom provider, a regional government body, and a university. In one intrusion, the ransomware reached 33+ hosts within two hours. If you run SharePoint on your own server and skipped last year's emergency patch, this is about you.
What actually happened
The Symantec and Carbon Black Threat Hunter Team report, published October 1, describes the chain step by step. The detailed intrusion ran from July 22 to 31, 2026:
- Initial access through ToolShell: CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771.
- Web shells dropped into SharePoint's LAYOUTS directory to steal the farm's ASP.NET machine keys. With those keys, attackers sign their own payloads and run code at will.
- Security tools disabled with a vulnerable K7 driver (CVE-2025-1055). This is "bring your own vulnerable driver."
- Remote access through Visual Studio Code's built-in tunnel, installed as a service. It looks like a developer tool, because it is one.
- Payloads staged on catbox.moe and Wasabi cloud storage.
- Ransomware pushed through the domain's SYSVOL share, which replicates to every domain controller and machine.
The victims are in Portuguese- and Spanish-speaking countries in Europe, Africa, and Latin America. The Hacker News has a summary.
Why the SharePoint ToolShell patch still matters for your business
A year-old bug is now the cheapest way into a network. Attackers don't need a zero-day when you didn't install last year's fix.
And patching alone is not enough. If the machine keys were stolen before you patched, the attacker can still forge requests. We said this about another SharePoint bug, and it applies again.
Our checklist for any on-prem SharePoint:
- Confirm the July 2025 ToolShell updates are installed. Then confirm every update since.
- Rotate the ASP.NET machine keys and restart IIS. Do this even if you think you patched on time.
- Look for unknown .aspx files in the LAYOUTS directory.
- Hunt for VS Code tunnels you didn't set up:
code tunnelservices, orcode-insiders.exeon a server. - Block unsigned and known-vulnerable drivers. Turn on Microsoft's vulnerable driver blocklist.
- Watch SYSVOL for new executables. Nothing should drop an .exe there without a change ticket.
Better question: does this file server need to be on-prem at all? For most small teams, SharePoint Online removes the patch job completely.
Key takeaways
- Symantec ties Warlock ransomware to four victims in two months, all entered via 2025 SharePoint ToolShell flaws
- Attackers stole ASP.NET machine keys, so patching without key rotation leaves the door open
- They disabled security tools with a vulnerable K7 driver and used a VS Code tunnel for remote access
- Ransomware spread through SYSVOL to 33+ hosts in two hours
- Patch, rotate machine keys, hunt for web shells and rogue tunnels, and enable the driver blocklist
Old servers are where the ransomware starts. We audit what's on-prem, patch or migrate it, and leave you with a named owner for every system. See what we do, or tell us what you're still running in the closet.
Sources: Symantec Threat Hunter Team, The Hacker News.
- #warlock
- #ransomware
- #sharepoint
- #toolshell
- #byovd
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
NetScaler SAML CVE-2026-88779 hits KEV: patch by October 7
CISA added Citrix NetScaler SAML flaw CVE-2026-88779 to KEV with a three-day deadline. Citrix says DoS. Researchers report a honeypot running malware.
Read itZammad CVE-2026-102489 on CISA KEV: patch your helpdesk
CISA added two exploited Zammad flaws to KEV. Chained, they turn a hijacked session into root on your helpdesk server. Upgrade to Zammad 7.2.0 and check for compromise.
Read it