{"id":5627,"date":"2025-07-25T10:03:32","date_gmt":"2025-07-25T10:03:32","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/07\/25\/hackers-exploiting-sharepoint-0-day-vulnerability-to-deploy-warlock-ransomware\/"},"modified":"2025-07-25T10:03:32","modified_gmt":"2025-07-25T10:03:32","slug":"hackers-exploiting-sharepoint-0-day-vulnerability-to-deploy-warlock-ransomware","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/07\/25\/hackers-exploiting-sharepoint-0-day-vulnerability-to-deploy-warlock-ransomware\/","title":{"rendered":"Hackers Exploiting Sharepoint 0-day Vulnerability to Deploy Warlock Ransomware"},"content":{"rendered":"<p>    Hackers Exploiting Sharepoint 0-day Vulnerability to Deploy Warlock Ransomware<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Microsoft has issued urgent warnings about active exploitation of critical SharePoint vulnerabilities CVE-2025-53770 and CVE-2025-53771 by multiple threat actors, including the China-based group Storm-2603, which has been deploying <a href=\"https:\/\/cybersecuritynews.com\/chinese-hackers-exploiting-sharepoint-servers-0-day\/\" target=\"_blank\" rel=\"noreferrer noopener\">Warlock ransomware<\/a> in compromised environments.\u00a0<\/p>\n<p>The vulnerabilities affect on-premises SharePoint Server 2016, 2019, and Subscription Edition, with exploitation attempts observed as early as July 7, 2025.<\/p>\n<pre class=\"wp-block-preformatted\"><strong><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-vivid-cyan-blue-color\">Key Takeaways<\/mark><\/strong><br>1. SharePoint zero-days CVE-2025-53770\/53771 have been used to deploy web shells since July\u00a0<br>2.\u00a0 Storm-2603, Linen\/Violet Typhoon spreading Warlock ransomware.<br>3. Apply updates, enable AMSI, rotate keys, and restart IIS.<\/pre>\n<h2 class=\"wp-block-heading\"><strong>Critical SharePoint Flaws Exploited<\/strong><\/h2>\n<p>The attack chain begins with the exploitation of <a href=\"https:\/\/cybersecuritynews.com\/cisa-chinese-hackers-sharepoint-0-day\/\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2025-49706<\/a>, a spoofing vulnerability, and <a href=\"https:\/\/cybersecuritynews.com\/cisa-chinese-hackers-sharepoint-0-day\/\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2025-49704<\/a>, a remote code execution flaw affecting internet-facing SharePoint servers.\u00a0<\/p>\n<p>Threat actors conduct reconnaissance through POST requests to the ToolPane endpoint, followed by deployment of malicious web shells named spinstall0.aspx and variants such as spinstall1.aspx and spinstall2.aspx.<\/p>\n<p>The web shell contains commands to retrieve ASP.NET MachineKey data, enabling attackers to steal cryptographic keys essential for session management and authentication.\u00a0<\/p>\n<p>Microsoft has identified the SHA-256 hash [<em>92bb4ddb98eeaf11fc15bb32e71d0a63256a0ed826a03ba293ce3a8bf057a514<\/em>] associated with the primary <em>spinstall0.aspx<\/em> payload.\u00a0<\/p>\n<p>Post-exploitation activities involve abuse of the w3wp.exe process that supports SharePoint, with attackers using cmd.exe and services.exe to disable Microsoft Defender protections through direct registry modifications.<\/p>\n<h2 class=\"wp-block-heading\"><strong>China\u2019s Warlock Ransomware<\/strong><\/h2>\n<p>Three primary threat actors have been identified exploiting these vulnerabilities: Linen Typhoon and Violet Typhoon, both established Chinese state-sponsored groups, and Storm-2603, which has escalated attacks to include ransomware deployment.\u00a0<\/p>\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXf4qcTls8p0kLxkuZkgy51nEPuDoOgmy67M5WvWS3KqqOnA-739rgH9aZU6vM218S_2hTsHWbLQEMC137m1HMH2yogCNcD2UY55xk2DY6aHfIDAQ65xHsmOUdZD6Ss-A5aB7UL1wA?key=iDjQSAgk86cm1-fEERQPIQ\" alt=\"\"><\/figure>\n<p>Storm-2603 establishes persistence through multiple mechanisms, including scheduled tasks and manipulation of Internet Information Services (IIS) components to load suspicious .NET assemblies.<\/p>\n<p>The group performs credential access using <a href=\"https:\/\/cybersecuritynews.com\/mimikatz-hacking-tool-to-deploy-trigona-ransomware\/\" target=\"_blank\" rel=\"noreferrer noopener\">Mimikatz<\/a> to target Local Security Authority Subsystem Service (LSASS) memory, extracting plaintext credentials for lateral movement via PsExec and the Impacket toolkit.\u00a0<\/p>\n<p>Command and control infrastructure includes domains such as update.updatemicfosoft.com and IP addresses 65.38.121.198 and 131.226.2.6.\u00a0<\/p>\n<p>The attack culminates with the modification of Group Policy Objects (GPOs) to distribute Warlock ransomware across compromised networks.<\/p>\n<p>Microsoft has released comprehensive security updates and strongly recommends immediate patching, enabling Antimalware Scan Interface (AMSI) in Full Mode, and rotating SharePoint server ASP.NET machine keys, followed by an IIS restart using iisreset.exe.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 97%,rgb(169,184,195) 100%)\">Experience faster, more accurate phishing detection and enhanced protection for your business with real-time sandbox analysis-&gt; <strong><a href=\"https:\/\/intelligence.any.run\/plans?utm_source=csn_jul&amp;utm_medium=article&amp;utm_campaign=freemium-exclusive&amp;utm_content=plans1&amp;utm_term=220725\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Try ANY.RUN now<\/a><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/sharepoint-0-day-ransomware-attack\/\">Hackers Exploiting Sharepoint 0-day Vulnerability to Deploy Warlock Ransomware<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Florence<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/sharepoint-0-day-ransomware-attack\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hackers Exploiting Sharepoint 0-day Vulnerability to Deploy Warlock Ransomware Microsoft has issued urgent warnings about active exploitation of critical SharePoint vulnerabilities CVE-2025-53770 and CVE-2025-53771 by multiple threat actors, including the China-based group Storm-2603, which has been deploying Warlock ransomware in compromised environments.\u00a0 The vulnerabilities affect on-premises SharePoint Server 2016, 2019, and Subscription Edition, with exploitation [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1383,129,63],"tags":[130],"class_list":["post-5627","post","type-post","status-publish","format-standard","hentry","category-cyber-attack-today","category-cyber-security","category-cyber-security-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/5627"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=5627"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/5627\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=5627"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=5627"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=5627"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}