The Warlock ransomware group, identified by Symantec as Longlegs, has been observed targeting a range of organizations, including a water utility, a telecommunications provider, a regional government body, and a university. These attacks, which have primarily focused on Portuguese and Spanish-speaking countries in Europe, Africa, and Latin America over the past two months, leverage vulnerabilities in Microsoft SharePoint for initial access.
The Warlock group first emerged in June 2025 and gained prominence a month later by exploiting a chain of zero-day vulnerabilities in Microsoft SharePoint, collectively known as ToolShell. These vulnerabilities are tracked as CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771. By August 2025, Microsoft noted that state-backed hacking groups Linen Typhoon and Violet Typhoon, along with the ransomware actor Storm-2603, were also utilizing ToolShell exploits.
In one intrusion beginning on July 22, the attackers deployed a tool designed to disable security software on at least 40 hosts within approximately two hours. Following this, Warlock ransomware was launched on at least 33 of these hosts. Initial access was typically gained by exploiting vulnerabilities in on-premises SharePoint deployments, after which a web shell compatible with multiple SharePoint versions was installed.
Symantec and Carbon Black researchers have observed that in some attacks attributed to Longlegs, an AV/EDR-killing tool was deployed using a bring your own vulnerable driver (BYOVD) technique. This involved exploiting a vulnerability (CVE-2025-1055) in a signed K7RKScan driver.
Analysis of the July 22 intrusion revealed that reconnaissance activities and the deletion of staging artifacts occurred two days after initial access was established. The ransomware payload was staged in the domain's SYSVOL share, a common method for distributing payloads across an entire network via logon scripts or Group Policy objects. The main executable for Visual Studio Code Insiders was also installed as a service to enable remote connections to compromised machines using VS Code's built-in tunneling capability. On one system, the open-source penetration testing framework NetExec was found, which aided the attackers in Active Directory enumeration, credential spraying, and remote command execution.
The final phase of the attack on July 31 involved the deployment of the AV/EDR killer, with Warlock ransomware appearing almost immediately after protection was disabled on each host. Researchers caution that ToolShell and other SharePoint vulnerabilities remain viable initial access vectors, despite more than a year passing since Warlock first exploited these flaws. Indicators of compromise for files and infrastructure used in these attacks have been provided by Symantec and Carbon Black threat hunters.






