Warlock Ransomware Uses Year-Old SharePoint ToolShell Flaws Against a Water Utility and a Telecom
TL;DR what: Warlock (Longlegs) broke into on-premises SharePoint servers at a water utility, a telecom provider, a regional government body and a university over two months, using the ToolShell vulnerabilities. impact: In one intrusion the group used a vulnerable K7RKScan driver to disable protection software on at least 40 hosts in about two hours, then pushed Warlock ransomware to 33 hosts from the domain SYSVOL share. fix: Microsoft released fixes for CVE-2025-49704, CVE-2025-49706, CVE-2025-53770 and CVE-2025-53771 in July 2025, and its ToolShell guidance also calls for rotating SharePoint
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in