216.73.217.22

From SharePoint Vulnerability Exploit to Enterprise Ransomware

· Published 20/08/2025 17:38 · Modified 20/08/2025 21:21

Export JSON

Essential information

Published
20/08/2025 17:38
Modified
20/08/2025 21:21
Tags
2025-08-20 CVE-2023-27532 credential-theft data exfiltration dll sideloading lateral movement lockbit lockbit 3.0 ransomware sharepoint vulnerability warlock
Related entities
1 intrusion sets (apt), 7 techniques (mitre), 2 malware, 6 others

Description

The group exploited unpatched Microsoft servers to gain initial access and deploy across enterprise environments. The attack chain involved exploiting vulnerabilities, privilege escalation through Group Policy modification, credential theft using Mimikatz, via SMB, and eventual deployment. Files were encrypted with a .x2anylock extension and data exfiltrated using RClone. The campaign targeted organizations globally across various industries. appears to be derived from leaked code and employs sophisticated evasion techniques like . The attack highlights the dangers of delayed patching and the importance of layered defenses.