Skip to content

Build1 publisher2 min readPublished Updated

Warlock operators ran an EDR killer on at least 40 machines within two hours

Symantec says Warlock operators ran an AV/EDR killer across at least 40 machines in roughly two hours after a suspected SharePoint compromise. The ransomware payloads moved between domain controllers through SYSVOL replication.

The Engineer · Build desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Illustration accompanying Warlock operators ran an EDR killer on at least 40 machines within two hours
Generated illustration

What happened

  • The Warlock binary and a ransom note were recorded on at least 33 hosts, though the report does not confirm that encryption completed on every one of them.
  • Symantec attributes the campaign to Longlegs, also tracked as Storm-2603, a group it assesses as having links to China.
  • At least four organizations were hit, among them water and telecommunications operators.
  • Attackers deployed an ASPX webshell on the SharePoint server and ran domain reconnaissance with commands such as net user /domain and nltest /domain_trusts.
  • Symantec also recorded DLL sideloading and Visual Studio Code tunnels used for remote access during the intrusion.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

  • exposure An on-prem SharePoint reachable on the network and joined to the domain gives an attacker a route from code execution on the web server to ransomware on the domain's controllers.
  • constraint SYSVOL replication and payload execution are separate steps, so watching replication between controllers will not tell defenders which hosts actually ran the payload.
  • capability The AV/EDR killer disabled defenses ahead of the ransomware, so endpoint agents a defender relies on can be switched off before anything encrypts.

The distribution channel was SYSVOL. Symantec and Carbon Black, in a report dated October 1, 2026, recorded the Warlock binary placed in the SYSVOL scripts directory, where DFS Replication between domain controllers carried it from one controller to the rest. [1][8] Placement by dfsrs.exe, the DFS Replication service, showed up on three other machines. [9]

The report treats replication and execution as separate steps. [8] The operators ran their own commands to copy run.exe and rune.exe out of SYSVOL onto individual hosts and launch them. [10] How those launch commands fired on each host is not established in the public report. [11]

At least 40 machines got the AV/EDR killer in roughly two hours, about one machine every three minutes. [3][1] Symantec notes those counts are not the enterprise-wide total of encrypted machines. [7]

Getting there takes more than a SharePoint foothold. Write access to SYSVOL is not the same as the right to modify Active Directory objects, and the attacker needs the SYSVOL write plus a path to execute on each host. [12] Execution has to run unblocked, and the process doing the encrypting needs write access to the target files; the report notes a working killer or a vulnerable driver is not strictly required. [13] A vulnerable driver was suspected here but not identified, and the same group abused the K7RKScan tool in other recent attacks. [17]

Entry required a SharePoint server reachable on the network, and Symantec has not pinned the exploit to a specific CVE. [14] The report lists four 2025 SharePoint flaws as related: CVE-2025-49704, CVE-2025-49706, CVE-2025-53770 and CVE-2025-53771. [15] Symantec recommends patching SharePoint. [16]

What to watch

  • Identification of the specific SharePoint CVE used for entry, or confirmation it was one of the four 2025 flaws listed.
  • Naming of the vulnerable driver behind the AV/EDR killer, after K7RKScan abuse in earlier attacks.
  • An enterprise-wide total of encrypted machines, which the 40 and 33 figures explicitly exclude.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories