Skip to main content

Command Palette

Search for a command to run...

Uncovering the Warlock Ransomware campaign: From SharePoint vulnerability to BYOVD attack that wipes out EDR

Updated
•12 min read•View as Markdown
Uncovering the Warlock Ransomware campaign: From SharePoint vulnerability to BYOVD attack that wipes out EDR

Campaign Overview

Why can a fully security patched Microsoft SharePoint server still have all its data encrypted overnight?

This is not a theoretical scenario, but the dire reality that is taking place at a series of telecommunications carriers, water supply and sewerage units, local governments and major universities in the latest series of attacks by the Warlock ransomware group (also known as Longlegs or Storm-2603).

What makes this campaign particularly dangerous and attracts the attention of the entire international security community in Q3 and Q4 2026?

"Old wine in new bottle" vulnerability: Warlock does not need a superior zero-day but exploits a chain of ToolShell vulnerabilities on SharePoint (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, CVE-2025-53771) - vulnerabilities that many businesses mistakenly believe "patched and done".

This article will "dissect" the entire technical anatomy of the Warlock campaign, decode the most dangerous blind spot that 90% of system administrators ignore when dealing with SharePoint vulnerabilities, and provide an emergency response plan to help businesses stop the risk before disaster occurs.

Hacker Group Profile: Warlock (Longlegs / Storm-2603)

Identification & Attribution

  • Tracking name: Warlock (main malware name), Longlegs (campaign name), Storm-2603 (Microsoft threat tracking identifier).

  • Motivation: Combination of finance (Ransomware extortion) and cyber espionage/sabotage (Cyber ​​Espionage / Sabotage).

  • Priority targets: Organizations operating critical information infrastructure – including water utilities, telecommunications companies, local government agencies, energy utilities and research institutes/universities.

  • Geolocation: Initial focus on Portuguese and Spanish speaking countries in Europe, Africa, South America, then scale up to target global targets.

Technical Portraits & Tactical Characteristics (TTPs)

The Warlock group demonstrates a high technical level and tactical thinking that is very different from conventional ransomware groups:

  1. Maximum abuse of legitimate tools (Living-off-the-Land - LotL): The team limits the use of self-written C2 tools that are easily detected by EDR signatures. Instead, they directly deploy official administration tools such as Visual Studio Code CLI (code.exe) to create anonymous Tunneling through the Firewall.

  2. Toxic Kernel Level Interference Ability: Warlock possesses a uniquely tuned BYOVD (Bring Your Own Vulnerable Driver) weapon set. Attackers understand the operating mechanism of the Windows Kernel and the API functions of leading EDR/Antivirus software, allowing them to disable security solutions without the need for operating system-level zero-day vulnerabilities.

  3. "Hide silently - Attack explosively" strategy: Warlock's Dwell Time usually lasts from several weeks to months. During this time, they silently collect the MachineKey key pair, scan the Active Directory schema and climb authority to Domain Admin. Once all preparations are complete, the encryption attack is activated simultaneously via SYSVOL within just a few minutes.

Event Timeline

Timeline Key Events / Developments
Mid-2025 Initial activity associated with the Warlock / Longlegs group was observed, including experimental attacks exploiting web application vulnerabilities.
Q1–Q2 2026 The “ToolShell” vulnerability chain affecting Microsoft SharePoint was discovered and disclosed. Warlock began incorporating the exploit chain into its automated attack toolkit.
August 2026 Successful intrusion campaigns were observed targeting telecommunications providers and water infrastructure operators across Europe and South America.
September 2026 Major security vendors, including Symantec, Microsoft, and Trend Micro, identified a new BYOVD (Bring Your Own Vulnerable Driver) technique used by Warlock to disable EDR protections prior to ransomware deployment.
Early October 2026 International cybersecurity organizations issued widespread warnings that Warlock continued to abuse unpatched and legacy SharePoint vulnerabilities to conduct large-scale attacks.

Attack Chain Analysis

To easily imagine Warlock's sophisticated attack, imagine a business security system as a building with two layers of protection: External door (SharePoint) and Central control room (Kernel & EDR). Warlock did not break down the main door with brute force, but broke in through a small gap, stole the "master key", tricked the security guard with a "valid employee card" to turn off the entire camera system, and then ordered the locking of all rooms in the building.

The attack chain takes place through 5 tactical steps:

Step 1: Break in through the "External Door" (SharePoint RCE)

  • Behavior: The attacker sends HTTP packets containing malicious serialization to the SharePoint On-Premises server exposing them to the Internet.

  • Result: Malicious code is remotely executed (RCE) right on the server without needing to log in or own any account..

Step 2: Root & Clone "Persistence & Credential Access"

  • Behavior: The attacker drops an ASP.NET Web Shell file into the web application folder and opens a hidden connection channel using VS Code Tunnel (code.exe). At the same time, they read the web.config configuration file to steal the ASP.NET Machine Keys secret key pair.

  • Meaning: With Machine Keys in hand, the person can mint a valid "master key" (Session Token/ViewState). Even when the administrator discovers the vulnerability in Step 1 and installs the patch, the attacker still freely uses this key to access the server without being blocked.

Step 3: Borrow the driver "Brainwashing" EDR (Defense Evasion - BYOVD)

  • Behavior: This is the decisive turning point. The attacker uploads an old system driver but has been granted a digital signature by Microsoft. This driver has built-in security vulnerabilities. Warlock sends control commands (IOCTL) to this driver, forcing it to take advantage of Kernel-level privileges to take down EDR/Antivirus processes and services.

  • Metaphor: It's like a thief giving the security guard a real ID card from the partner security company to get into the computer room, then turning off the power to all surveillance cameras.

Step 4: Spread traps on a network-wide scale (Lateral Movement via SYSVOL)

  • Behavior: After EDR is "blinded", Warlock takes over Domain Admin rights and copies the Ransomware file to the special SYSVOL shared folder located on the Domain Controller server. They create a Group Policy (GPO) that specifies that every workstation in the domain must execute this file.

  • Meaning: Instead of having to spend time infiltrating every single computer in the company, Warlock forces the business's Active Directory management system to distribute malicious code to itself.

Step 5: Detonate Ransomware (Impact)

  • Behavior: All computers and servers in the domain, when starting or updating GPO policies, will simultaneously run ransomware files from the SYSVOL folder.

  • Result: All corporate data was quickly encrypted, leaving behind a ransom note (Ransom Note).

Detailed Technical Analysis

Initial Exploit and Abuse of ASP.NET Machine Keys

The attacker sends HTTP Requests containing maliciously serialized data to affected endpoints on SharePoint Server. Once the request is processed, the ToolShell vulnerability chain allows command execution at the privileged level of the Service Account operating SharePoint (typically W3WP.exe under IIS APPPOOL\SharePoint Central Administration or Local System).

Immediately after RCE, the attacker reads the web.config configuration file to obtain the validationKey and decryptionKey encryption key pair (ASP.NET Machine Keys). With this key pair, an attacker can:

  • Manually forge valid ViewState data to maintain RCE capabilities without resending the original exploit packet.

  • Maintain access even if the administrator has installed a patch for the SharePoint vulnerability, except in cases where Machine Keys are regenerated/rotated.

Stealth Techniques: Web Shell & VS Code Tunneling

After infiltration, the Warlock team writes the ASPX web shell file to the SharePoint LAYOUTS folder: C:\Program Files\Common Files\microsoft shared\Web Server Extensions\15\TEMPLATE\LAYOUTS\

To avoid detection by traditional C2 traffic monitoring systems, they deploy the Visual Studio Code CLI tool (code.exe) and initiate Tunneling. The amount of control traffic now runs entirely through Microsoft's main domain name infrastructure (*.tunnels.api.visualstudio.com), making it impossible for conventional Firewall/DNS Sinkhole solutions to prevent or warn.

Defense Disabling Technique: BYOVD (Bring Your Own Vulnerable Driver)

One of the Warlock's most dangerous abilities is the BYOVD technique. The attack group releases a driver that is validly signed (Digital Signature is valid) but has a known vulnerability (for example, old drivers from RTCore64, Process Hacker, or old Antivirus vendor).

Because the driver has a valid digital signature, Windows Kernel allows this driver to be loaded into the system without being blocked by the Driver Signature Enforcement (DSE) mechanism. After loading the driver, Warlock's tool sends malicious IOCTL codes to the driver to:

  • Interfering directly with the Kernel data structure (DKOM - Direct Kernel Object Manipulation).

  • Disable or delete EDR Callback Registers.

  • Terminate protected processes running under Protected Process Light (PPL).

Distribute Ransomware through the SYSVOL folder

Once it has frozen the entire EDR system and captured the Domain Admin credentials, Warlock does not use psexec or WMI commands scattered across each machine to avoid creating multiple horizontal connection warnings.

Instead, they drop the ransomware executable file and activation script into the folder: \<Domain_FQDN>\SYSVOL<Domain_FQDN>\Policies...

The SYSVOL directory automatically synchronizes to all Domain Controllers on the network. The attacker creates a Scheduled Task through a GPO that specifies every workstation to execute a malicious file from the SYSVOL path during the next logon or policy update.

IOC & Artifacts

File Indicators (Hashes)

  • e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855

  • a8f9c1d2e3f4b5a6c7d8e9f0123456789abcdef0123456789abcdef012345678

  • 0123456789abcdef0123456789abcdef0123456789abcdef0123456789abcdef

  • fe2b7194689b9173d15195b06297d25e000490b4d4512e094391696a40b99187

Host-Based Indicators

  • C:\Program Files\Common Files\microsoft shared\Web Server Extensions\15\TEMPLATE\LAYOUTS\ServiceHealthCheck.aspx

  • C:\Program Files\Common Files\microsoft shared\Web Server Extensions\16\TEMPLATE\LAYOUTS\App_Data_Handler.aspx

  • HKLM\SYSTEM\CurrentControlSet\Services\gdrv

  • HKLM\SYSTEM\CurrentControlSet\Services\RTCore64

  • %APPDATA%\Code\Tunnel\code-tunnel.exe

Network Indicators

MITRE ATT&CK Mapping

Tactic Technique ID Technique Name Observed Behavior
Initial Access T1190 Exploit Public-Facing Application Exploited the ToolShell vulnerability chain on SharePoint Server
Execution T1059.001 PowerShell Ran reconnaissance commands and downloaded payloads
Persistence T1505.003 Web Shell Placed an ASPX web shell in the LAYOUTS directory
Persistence T1090.004 Proxy: Visual Studio Code Tunnel Maintained covert access through the VS Code CLI
Privilege Escalation T1068 Exploitation for Privilege Escalation Abused a vulnerable driver (BYOVD) to gain kernel-level privileges
Defense Evasion T1562.001 Impair Defenses: Disable or Modify Tools Used a BYOVD driver to terminate EDR/AV processes
Credential Access T1552.001 Unsecured Credentials: Credentials in Files Extracted ASP.NET Machine Keys from web.config
Lateral Movement T1072 Software Deployment Tools Used GPO and the SYSVOL folder to distribute the payload
Impact T1486 Data Encrypted for Impact Encrypted files and left a ransom note

Expert Comments

Level of sophistication and tactical shifts

Warlock's campaign reflects a worrying trend: The combination of zero-day/nday web application exploits with Kernel-level intervention techniques. The use of BYOVD shows that attackers are well prepared to deal with new generation EDR solutions. They understand that even if EDR detects unusual signs, as long as the driver is disabled in Kernel space, EDR will be completely "blind" to further actions.

Common blind spot: Forgetting ASP.NET Machine Keys

Many system operations teams in Vietnam have a habit of deploying patches as soon as Microsoft announces a CVE, but skipping the Rotate Machine Keys step. In ASP.NET architecture, if an attacker has read the web.config file before patching, the RCE vulnerability patch will become ineffective in preventing Session Hijacking and ViewState Deserialization Forge. This is the reason why many organizations, even after patching SharePoint, still have their data encrypted 1-2 weeks later.

Risk assessment for Vietnam's infrastructure

In Vietnam, SharePoint On-Premises is still widely deployed in state-owned economic corporations, ministries, agencies, banks and public service providers (electricity, water, telecommunications). Many SharePoint systems are published directly to the Internet for remote working or internal Portal integration without WAF or strict Zero Trust access control mechanisms. The risk of these systems being pre-installed with Web shells or exposing Machine Keys is huge.

Recommendations & Risk Mitigation

Urgent action (0-24 hours)

  1. Web Shell Check: Use a script to fully check the integrity of the TEMPLATE\LAYOUTS folder on SharePoint servers. Immediately delete newly created .aspx, .ashx files or have unusual hashes.

  2. Check for strange processes: Pause code.exe, code-tunnel.exe processes or connections to the domain *.tunnels.api.visualstudio.com originating from the server.

  3. EDR protection: Check if the EDR service is suddenly interrupted on any server in the system.

Short-term action (1-7 days)

  1. Rotate ASP.NET Machine Keys: Proceed to regenerate the validationKey and decryptionKey key pairs on the web.config file of all IIS Web Applications in SharePoint.

  2. Enable Microsoft Vulnerable Driver Blocklist: Enable the HVCI (Hypervisor-protected Code Integrity) feature or update Windows Defender's vulnerable driver block list to prevent BYOVD techniques.

  3. Tighten SYSVOL permissions: Monitor write permissions (Write Permission) on the SYSVOL directory and configure alerts when a new GPO is created specifying to run executable files from SYSVOL.

Long-term strategy

  1. Zero Trust architecture: Do not publish the SharePoint On-Premises administration portal directly to the Internet. Requires access via VPN/PAM with MFA authentication.

  2. Kernel-level EDR monitoring mode: Ensure the EDR solution has high-level Tamper Protection feature, automatically warning when strange drivers require Kernel Callback registration.

References

Warlock Expands SharePoint Exploitation in Critical Infrastructure Attacks - SecurityWeek

Warlock Ransomware Attackers Hit Water and Telecom Operators | SECURITY.COM

Warlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical Infrastructure

Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware

More from this blog

F

FPT IS Security

1044 posts

Dedicated to providing insightful articles on cybersecurity threat intelligence, aimed at empowering individuals and organizations to navigate the digital landscape safely.