
Warlock Ransomware Escalates Global Campaign Targeting Critical Infrastructure via SharePoint Exploits
The China-linked Warlock group has launched a series of high-impact attacks against water utilities and telecom providers. The campaign leverages a sophisticated chain of zero-day vulnerabilities known as ToolShell.
Encrygma is selling the entire Full Cyber Weapon Research of Warlock Ransomware Escalates Global Campaign Targeting Critical Infrastructure via SharePoint Exploits for ₿ 0.10 BTC. Contact us.
Executive Takeaway — TL;DR
- Category:
- Threat Intelligence
- Severity:
- Critical
- Actor Type:
- APT
- Geography:
- Global
- Confidence:
- Confirmed
- CVE:
- CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, CVE-2025-53771
- Source:
- BleepingComputer
- Read Time:
- 4 min
Executive Summary
As of October 2026, the threat landscape has been significantly disrupted by the Warlock ransomware group, which has intensified its operations against critical infrastructure. Recent intelligence confirms that the group is actively exploiting a chain of zero-day vulnerabilities in Microsoft SharePoint, identified as the 'ToolShell' exploit chain (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771). These attacks have targeted water utilities, telecommunications providers, and regional government bodies, primarily in Portuguese and Spanish-speaking regions across Europe, Africa, and Latin America.
Threat Analysis
Warlock, which emerged in June 2025, has demonstrated a high level of operational maturity. By focusing on critical infrastructure, the group aims to maximize leverage for double-extortion demands. Unlike opportunistic cybercriminal gangs, Warlock exhibits a strategic preference for sectors that cannot afford prolonged downtime, thereby increasing the likelihood of ransom payment. The group's recent activity indicates a shift toward broader geographic targeting, moving beyond its initial operational theaters to exploit vulnerabilities in global enterprise software deployments.
Technical Details
The core of Warlock's current campaign is the ToolShell exploit chain. This chain allows for remote code execution (RCE) on unpatched Microsoft SharePoint servers. Once initial access is established, the attackers deploy custom post-exploitation tools to escalate privileges and move laterally through the victim's network. The group utilizes advanced obfuscation techniques to bypass traditional endpoint detection and response (EDR) solutions. Following data exfiltration, the group deploys its proprietary ransomware payload, which is designed to encrypt both Windows and Linux environments, including virtualized infrastructure such as ESXi servers.
Attribution Assessment
Intelligence analysts attribute Warlock to China-linked threat actors based on the group's TTPs (Tactics, Techniques, and Procedures) and the specific nature of their target selection. The sophistication of the ToolShell exploit chain suggests access to significant research and development resources, consistent with state-aligned or state-sponsored cybercriminal entities operating under a ransomware-as-a-service (RaaS) or independent model.
Implications
The targeting of water and telecom sectors poses a severe risk to public safety and national security. The use of zero-day vulnerabilities in widely deployed enterprise software like SharePoint means that organizations are often compromised before they have the opportunity to apply security patches. This creates a 'window of vulnerability' that Warlock is aggressively exploiting to maintain its momentum.
Recommendations
Organizations utilizing Microsoft SharePoint must prioritize the immediate application of all security updates and monitor for indicators of compromise (IoCs) related to the ToolShell exploit chain. It is recommended that entities implement strict network segmentation to isolate critical infrastructure from public-facing web services. Furthermore, organizations should enhance their incident response plans to include specific playbooks for double-extortion scenarios, ensuring that offline, immutable backups are maintained and tested regularly.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

ThreeAM and Morpheus Ransomware Groups Launch Coordinated Global Attacks in October 2026

ThreeAM and Morpheus Ransomware Groups Launch Coordinated Global Extortion Campaigns

