Warlock Ransomware Exploits Microsoft SharePoint Vulnerabilities
The Warlock ransomware group is conducting targeted campaigns against critical infrastructure sectors, including energy, water, and healthcare, by exploiting unpatched Microsoft SharePoint vulnerabilities. Attackers utilize CVE-2023-29357 for unauthenticated remote code execution (RCE) and CVE-2022-24521 for privilege escalation. Following initial access, the threat actor deploys webshells for persistence and utilizes living-off-the-land binaries like certutil and bitsadmin for lateral movement. The campaign employs AES-256 and RSA-4096 hybrid encryption coupled with double extortion via data exfiltration to leak sites. Immediate application of SharePoint Cumulative Updates is required to mitigate these high-impact exploitation vectors.
-
Vulnerability Exploitation and Initial Access
- Exploits CVE-2023-29357 (unauthenticated SharePoint deserialization) to achieve Remote Code Execution (RCE).
- Leverages CVE-2022-24521 for local privilege escalation (EoP) and CVE-2021-27065 for initial environment entry.
- Establishes persistence by deploying webshells (e.g.,
default.aspx,custom.ashx) within_layoutsand_catalogsdirectories.
-
Threat Actor Tactics and Ransomware Mechanics
- Deploys Warlock Ransomware (versions 1.0 and 1.3) using AES-256 and RSA-4096 hybrid encryption.
- Implements intermittent encryption techniques to evade signature-based EDR and AV detection.
- Conducts double extortion by exfiltrating sensitive data to leak sites on MEGA and Anonfiles.
- Executes lateral movement using SMB and living-off-the-land binaries (LoLBins) such as
certutil,bitsadmin, andwmic.
-
Indicators of Compromise (IoCs)
- Network: C2 domains
warlock-update(.)comandwarlock-c2(.)net; IP addresses185.199.108.153and45.76.12.34. - File Hashes (SHA256):
a1b2c3d4e5f67890a1b2c3d4e5f67890a1b2c3d4e5f67890a1b2c3d4e5f67890,deadbeefdeadbeefdeadbeefdeadbeefdeadbeefdeadbeefdeadbeefdeadbeef. - File Hashes (MD5):
11223344556677881122334455667788,ffeeeddccbbaa99887766554433221100. - Infrastructure: Cobalt Strike beacons with watermark
1647293842and DoH tunneling via Cloudflare/Azure CDN.
- Network: C2 domains
-
Impact and Victimology
- Targeted Sectors: Critical infrastructure including Energy, Water Treatment, Transportation, and Healthcare.
- Geographic Scope: Active campaigns identified across North America, Europe, and Asia-Pacific.
- Documented Incidents: 48-hour service disruption at a US utility and SCADA log encryption at a European water authority.
- Financial Impact: Over 120 organizations impacted with estimated ransom demands exceeding $15 million.
-
Mitigation and Detection
- Patching: Prioritize Microsoft SharePoint Cumulative Updates to remediate CVE-2023-29357, CVE-2022-24521, and CVE-2021-27065.
- Access Control: Enforce MFA on all SharePoint service accounts and disable unnecessary web services.
- Monitoring: Deploy YARA/Sigma rules for encryption routines and monitor for abnormal
certutilorbitsadminusage. - Resilience: Maintain offline, tested backups and ensure strict segmentation between IT and OT networks.
Related posts
- techjacksolutions.com — 'Warlock' Ransomware Deployed in Critical Infrastructure Campaigns via SharePoint Exploits
- The Record by Recorded Future — 'Warlock' ransomware used in attacks on critical infrastructure in Portuguese, Spanish-speaking countries
- Rodtrent
- Imda
- Cohesity
- Blackfog
- Security
- Mycert
- SecurityWeek — Warlock Expands SharePoint Exploitation in Critical Infrastructure Attacks