China-Linked Warlock Ransomware Exploits SharePoint Zero-Days in Critical Infrastructure
The Warlock/Longlegs group leveraged a chained set of zero-day SharePoint vulnerabilities (ToolShell) to breach critical infrastructure organizations including water utilities, telecom providers, and government bodies — sectors where operational disruption carries severe public safety consequences. Because these were zero-days, organizations had no vendor patch to apply at the time of initial exploitation, making layered defenses and rapid detection the primary lines of defense. The attackers also deliberately disabled endpoint protection before deploying ransomware, indicating a sophisticated, multi-stage intrusion methodology designed to blind defenders. This highlights that unpatched or inherently vulnerable internet-facing collaboration platforms represent a high-value attack surface, especially in critical infrastructure where legacy software and delayed patch cycles are common. The combination of zero-day exploitation and endpoint defense evasion underscores the need for defense-in-depth rather than reliance on any single security control.
Tactical Insight
Immediate actions
- Apply all available SharePoint patches immediately and subscribe to Microsoft Security Response Center (MSRC) advisories for emergency out-of-band updates.
- Restrict external internet access to SharePoint environments using firewall rules or a reverse proxy, exposing them only through a hardened VPN or Zero Trust gateway.
- Audit and verify that endpoint detection and response (EDR) solutions cannot be disabled by non-privileged or standard admin accounts.
Long-term improvements
- Implement a formal emergency patching procedure with SLAs under 24–48 hours for critical internet-facing assets in critical infrastructure environments.
- Enforce network segmentation so that SharePoint servers and collaboration platforms are isolated from OT/SCADA systems and cannot serve as a pivot point into operational networks.
- Maintain an up-to-date asset inventory of all internet-facing services and conduct regular attack surface reviews to identify exposure before adversaries do.
Detection measures
- Deploy behavioral monitoring and SIEM rules tuned to detect anomalous SharePoint API calls, unexpected admin privilege escalation, and EDR service termination attempts.
- Enable centralized, tamper-resistant logging for all SharePoint activity and route alerts to a 24/7 SOC or managed detection and response (MDR) provider.
- Conduct regular threat hunting exercises specifically targeting lateral movement patterns consistent with ransomware precursor activity (e.g., credential dumping, defense evasion techniques).