Warlock, a China-linked ransomware group, targeted multiple organizations including a water utility, telecom provider, regional government body, and a university by exploiting SharePoint vulnerabilities for initial access. The attackers used ToolShell flaws, deployed an EDR-killing tool, and staged Warlock ransomware across compromised networks before launching encryption. #Warlock #ToolShell #Longlegs #K7RKScan #MicrosoftSharePoint
Keypoints
- Warlock targeted victims across Europe, Africa, and Latin America.
- The group used SharePoint vulnerabilities to gain initial access.
- Symantec links Warlock to the threat actor Longlegs.
- An AV/EDR killer disabled protection on at least 40 hosts.
- VS Code tunneling and NetExec were used during the intrusion.