Build1 publisher2 min readPublished Updated
Warlock operators ran an EDR killer on at least 40 machines within two hours
Symantec says Warlock operators ran an AV/EDR killer across at least 40 machines in roughly two hours after a suspected SharePoint compromise. The ransomware payloads moved between domain controllers through SYSVOL replication.
The Engineer · Build desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- The Warlock binary and a ransom note were recorded on at least 33 hosts, though the report does not confirm that encryption completed on every one of them.
- Symantec attributes the campaign to Longlegs, also tracked as Storm-2603, a group it assesses as having links to China.
- At least four organizations were hit, among them water and telecommunications operators.
- Attackers deployed an ASPX webshell on the SharePoint server and ran domain reconnaissance with commands such as net user /domain and nltest /domain_trusts.
- Symantec also recorded DLL sideloading and Visual Studio Code tunnels used for remote access during the intrusion.
Compiled by The EngineerSomething wrong?How this is made
Why it matters
- exposure An on-prem SharePoint reachable on the network and joined to the domain gives an attacker a route from code execution on the web server to ransomware on the domain's controllers.
- constraint SYSVOL replication and payload execution are separate steps, so watching replication between controllers will not tell defenders which hosts actually ran the payload.
- capability The AV/EDR killer disabled defenses ahead of the ransomware, so endpoint agents a defender relies on can be switched off before anything encrypts.
The distribution channel was SYSVOL. Symantec and Carbon Black, in a report dated October 1, 2026, recorded the Warlock binary placed in the SYSVOL scripts directory, where DFS Replication between domain controllers carried it from one controller to the rest. [1][8] Placement by dfsrs.exe, the DFS Replication service, showed up on three other machines. [9]
The report treats replication and execution as separate steps. [8] The operators ran their own commands to copy run.exe and rune.exe out of SYSVOL onto individual hosts and launch them. [10] How those launch commands fired on each host is not established in the public report. [11]
At least 40 machines got the AV/EDR killer in roughly two hours, about one machine every three minutes. [3][1] Symantec notes those counts are not the enterprise-wide total of encrypted machines. [7]
Getting there takes more than a SharePoint foothold. Write access to SYSVOL is not the same as the right to modify Active Directory objects, and the attacker needs the SYSVOL write plus a path to execute on each host. [12] Execution has to run unblocked, and the process doing the encrypting needs write access to the target files; the report notes a working killer or a vulnerable driver is not strictly required. [13] A vulnerable driver was suspected here but not identified, and the same group abused the K7RKScan tool in other recent attacks. [17]
Entry required a SharePoint server reachable on the network, and Symantec has not pinned the exploit to a specific CVE. [14] The report lists four 2025 SharePoint flaws as related: CVE-2025-49704, CVE-2025-49706, CVE-2025-53770 and CVE-2025-53771. [15] Symantec recommends patching SharePoint. [16]
What to watch
- Identification of the specific SharePoint CVE used for entry, or confirmation it was one of the four 2025 flaws listed.
- Naming of the vulnerable driver behind the AV/EDR killer, after K7RKScan abuse in earlier attacks.
- An enterprise-wide total of encrypted machines, which the 40 and 33 figures explicitly exclude.