Executive Summary
The China-linked Warlock ransomware group (also tracked as Longlegs and Storm-2603) conducted a sophisticated attack campaign targeting critical infrastructure including water utilities, telecom providers, regional governments, and universities across Portuguese and Spanish-speaking regions. The group exploited the ToolShell vulnerability chain (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771) in Microsoft SharePoint deployments to gain initial access, then deployed EDR-killing tools via BYOVD techniques affecting up to 40 hosts within two hours before executing ransomware on 33 systems.
This incident highlights the growing convergence of state-sponsored APT tactics with ransomware operations, demonstrating how sophisticated threat actors are increasingly targeting critical infrastructure through supply chain vulnerabilities and leveraging legitimate tools like Visual Studio Code tunneling for persistence and remote access.
Why This Matters Now
Critical infrastructure faces escalating threats as ransomware groups adopt nation-state level tactics, exploiting unpatched SharePoint vulnerabilities that remain viable attack vectors over a year after disclosure, requiring immediate attention to hybrid cloud security and zero-trust segmentation.
Attack Path Analysis
Warlock ransomware group exploited SharePoint vulnerabilities (ToolShell CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, CVE-2025-53771) to gain initial access to critical infrastructure networks. After establishing persistence via web shells, attackers escalated privileges through Active Directory enumeration and credential spraying using NetExec framework. They moved laterally across 40+ hosts within two hours, established command and control using VS Code tunneling capabilities, and deployed EDR-killing tools via BYOVD technique before staging Warlock ransomware in SYSVOL for domain-wide execution.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Exploited SharePoint ToolShell vulnerabilities (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, CVE-2025-53771) targeting water utility, telecom provider, regional government, and university on-premises SharePoint deployments
Related CVEs
CVE-2025-49704
CVSS 8.8A remote code execution vulnerability in Microsoft SharePoint Server that allows an authenticated attacker to execute arbitrary code via crafted requests.
Affected Products:
Microsoft SharePoint Server – 2019, 2016, Subscription Edition
Exploit Status:
exploited in the wildCVE-2025-49706
CVSS 6.5A privilege escalation vulnerability in Microsoft SharePoint Server that allows an attacker to gain elevated permissions on the system.
Affected Products:
Microsoft SharePoint Server – 2019, 2016, Subscription Edition
Exploit Status:
exploited in the wildCVE-2025-1055
CVSS 5.6A privilege escalation vulnerability in K7RKScan driver that allows an attacker to execute code with kernel privileges via BYOVD technique.
Affected Products:
K7 Computing K7RKScan Driver – < 16.0.0.270
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Web Shell
File and Directory Discovery
Disable or Modify Tools
Exploitation for Privilege Escalation
Remote Desktop Protocol
Data Encrypted for Impact
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Software Security Framework
Control ID: 6.2.4
NYDFS 23 NYCRR 500 – Penetration Testing and Vulnerability Assessments
Control ID: 500.15
DORA – ICT Risk Management
Control ID: Article 11
CISA ZTMM 2.0 – Identity and Access Management
Control ID: Identity
NIS2 Directive – Cybersecurity Risk Management
Control ID: Article 21
ISO 27001 – Management of Technical Vulnerabilities
Control ID: A.12.6.1
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Utilities
Water utilities face critical ransomware exposure through SharePoint vulnerabilities, with operational disruption risks and compliance failures under critical infrastructure regulations.
Telecommunications
Telecom providers vulnerable to Warlock ransomware via SharePoint exploits, threatening network operations and customer data with severe regulatory and business continuity impacts.
Government Administration
Regional government bodies targeted by China-linked ransomware using SharePoint zero-days, compromising public services and sensitive citizen data through privilege escalation attacks.
Higher Education/Acadamia
Universities face ransomware threats exploiting SharePoint vulnerabilities, risking research data and student information through lateral movement and inadequate east-west traffic security.
Sources
- Warlock ransomware breach SharePoint in water, telecom operator attackshttps://www.bleepingcomputer.com/news/security/warlock-ransomware-breach-sharepoint-in-water-telecom-operator-attacks/Verified
- Microsoft SharePoint zero-day exploited in RCE attacks, no patch availablehttps://www.bleepingcomputer.com/news/microsoft/microsoft-sharepoint-zero-day-exploited-in-rce-attacks-no-patch-available/Verified
- Warlock Ransomware Critical Infrastructure Analysishttps://www.security.com/threat-intelligence/warlock-ransomware-critical-infrastructureVerified
- Microsoft Security Response Center Advisoryhttps://msrc.microsoft.com/security-guidanceVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely have significantly constrained Warlock ransomware's ability to rapidly spread across 40+ hosts and execute domain-wide encryption. The segmented architecture could have reduced blast radius by limiting lateral movement pathways and controlling east-west traffic flows within the compromised infrastructure networks.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While initial SharePoint exploitation may still occur, CNSF fabric visibility would likely have enabled faster detection of anomalous web shell activity and constrained the attacker's ability to establish deeper persistence across multiple infrastructure segments.
Control: Zero Trust Segmentation
Mitigation: Zero trust segmentation would likely have limited the scope of Active Directory enumeration activities and constrained credential spraying effectiveness by restricting access pathways between network segments and reducing the attack surface for privilege escalation.
Control: East-West Traffic Security
Mitigation: East-west traffic controls would likely have significantly constrained the rapid lateral movement by enforcing micro-segmentation policies that limit host-to-host communication pathways, potentially reducing the scope from 40+ compromised systems to isolated network segments.
Control: Multicloud Visibility & Control
Mitigation: Multicloud visibility controls would likely have detected the unauthorized VS Code tunneling service installation and constrained command and control communications by identifying anomalous outbound connection patterns from critical infrastructure systems.
Control: Egress Security & Policy Enforcement
Mitigation: Egress security controls would likely have constrained data exfiltration activities by monitoring and limiting outbound data flows from critical infrastructure systems, reducing the volume of sensitive information that could be transferred to external command and control infrastructure.
Despite ransomware execution on compromised systems, the segmented architecture would likely have contained encryption impact to isolated network segments rather than allowing unrestricted domain-wide propagation, potentially limiting affected assets in water utility, telecom, and government infrastructure.
Impact at a Glance
Affected Business Functions
- Water Treatment Operations
- Telecommunications Infrastructure
- Public Services
- Educational Systems
Estimated downtime: 18 days
Estimated loss: $2,500,000
Critical infrastructure operational data, customer telecommunications records, university student and faculty information, and municipal government citizen data across Portuguese and Spanish speaking regions
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation with identity-based policies to prevent rapid lateral movement across 40+ hosts within hours
- • Deploy Egress Security & Policy Enforcement to detect and block unauthorized data exfiltration and C2 tunneling activities like VS Code remote access
- • Enable East-West Traffic Security controls to monitor and restrict internal network flows during Active Directory enumeration and credential spraying attempts
- • Establish Multicloud Visibility & Control to detect anomalous automation patterns, suspicious tool deployment, and EDR disabling activities in real-time
- • Configure Threat Detection & Anomaly Response capabilities to identify covert remote access tools and baseline deviations during reconnaissance phases



