StratosAlly – Cybersecurity for digital safety

Warlock Ransomware Uses SharePoint Flaws to Disable Security and Spread Across Networks

Picture of StratosAlly

StratosAlly

Warlock ransomware attack spreading from a SharePoint server to Windows computers across a network

Warlock ransomware operators are continuing to target vulnerable Microsoft SharePoint servers, using them as an entry point into larger Windows environments.

The group is also known as Longlegs, Storm-2603 and Gold Salem. Recent attacks have affected organizations in Portuguese- and Spanish-speaking countries, including a water utility, a telecom provider, a regional government body and a university.

The initial access still appears to come from exposed or unpatched SharePoint systems.

The SharePoint server is only the starting point. After breaking in, Warlock operators have been seen planting a web shell and searching the server for useful configuration data. That includes SharePoint’s ASP.NET machine keys. With access to those keys, the attackers can generate requests the application is more likely to trust and use that access to run code on the compromised system.

The group has been seen using DLL sideloading, public file-hosting services and normal Windows commands to continue the intrusion. Researchers also observed the use of Visual Studio Code tunneling for remote access, which can make the connection look less unusual inside a business network.

Another important part of the attack is disabling security software before ransomware is launched.

Warlock operators have abused a vulnerable driver called K7RKScan as part of a Bring Your Own Vulnerable Driver, or BYOVD, technique. In one incident, a tool used to interfere with security products was pushed to at least 40 systems in about two hours. Warlock ransomware later appeared on at least 33 hosts.

The attackers also made use of Active Directory’s SYSVOL share.

Rather than copying the ransomware to every machine one by one, they placed it in a location that Windows already replicates across the domain. That allowed normal domain replication to help spread the malicious file.

The activity shows why patching SharePoint is only one part of the response.

Organizations running on-premises SharePoint should also check for web shells, unusual changes on SharePoint servers, unexpected drivers, suspicious Visual Studio Code tunnel activity and unfamiliar files appearing in SYSVOL.

Warlock’s continued use of older SharePoint flaws is another reminder that attackers will keep using known vulnerabilities as long as exposed systems remain available.

Let’s refine your stalking skills; go through our Instagram and LinkedIn. 

more Related articles