Thursday, October 30, 2025

A Deep Dive Into Warlock Ransomware Deployed Via ToolShell SharePoint Chained Vulnerabilities

Author(s): Vlad Pasca
  • Warlock ransomware was deployed by exploiting the SharePoint vulnerabilities CVE-2025-53770 and CVE-2025-53771
  • The malware includes a hostname verification mechanism that excludes designated systems from encryption, indicating self-preservation tactics
  • Warlock performs defense evasion by stopping a list of services and processes and removes volume shadow copies 
  • The ransomware encrypts files using a combination of the ChaCha20 algorithm and Curve25519

Warlock ransomware has been recently found being distributed through newly discovered SharePoint vulnerabilities. This malware represents the latest evolution in ransomware tactics, combining advanced encryption methods with targeted defense evasion techniques.

As a result, we have conducted a comprehensive analysis of Warlock, examining both its initial behavior through sandbox environments and performing detailed static and dynamic analysis of samples in the wild. The findings reveal a methodical attack pattern designed to maximize damage while protecting itself from detection and removal.

The ransomware exploits two critical SharePoint vulnerabilities (CVE-2025-53770 and CVE-2025-53771) as its entry point, then deploys a multi-stage attack that includes terminating security services, removing recovery options, and implementing a hybrid encryption scheme using ChaCha20 and Curve25519 algorithms.

Perhaps most telling is Warlock's self-preservation mechanism—a hostname verification feature that deliberately avoids encrypting certain systems, suggesting a calculated self-preservation approach built by its operators.

A Hybrid Analysis Perspective

As we can see in the Hybrid Analysis report, the ransomware appends its extension to the existing one:

Figure 1 - Warlock ransomware’s extension identified

Figure 2 reveals that the malware is looking to open and possibly stop multiple services related to backup, databases,  shadow copies, AntiVirus software, and so on.

Figure 2 - Multiple services are targeted

Hybrid Analysis identifies that the sample implements the ChaCha20 algorithm for encryption using YARA rules (Figure 3).

Figure 3 - ChaCha20 algorithm identified

Figure 4 - CryptoPP library is statically linked

The SHEmptyRecycleBinW API is utilized to empty the Recycle Bin in order to avoid possible file recovery from the location:

Figure 5 - SHEmptyRecycleBinW API call

A Deeper Dive Into Warlock

The process retrieves the command-line arguments and compares them with the following list: “-e” (doesn’t change the extension of the file passed as a parameter), “-n” (doesn’t create the ransom note) and “-p”.

Figure 6 - Command-line arguments retrieval

The threat actor embedded a GUID in the code that will appear in all encrypted files. The ransomware also implements a check (skipping files encryption) for a placeholder that should be a hostname called “replacethiswhitehost”.

Figure 7 - Hard-coded information

The malware hides the current window via a function call to ShowWindow (0x0 = SW_HIDE):

Figure 8 - Malware’s window is hidden

SHEmptyRecycleBinW is used to empty the Recycle Bin on all drives (0x7 = SHERB_NOCONFIRMATION | SHERB_NOPROGRESSUI | SHERB_NOSOUND):

Figure 9 - Empty the Recycle Bin

Warlock mounts all unmounted volumes using the FindFirstVolumeW, FindNextVolumeW, and SetVolumeMountPointW functions.

Figure 10 - Mount all unmounted volumes

Defense Evasion

The ransomware stops a list of services (i.e. AntiVirus, backup, shadow copies) using the ControlService method (0x1 = SERVICE_CONTROL_STOP). The entire list of services can be found in the Appendix.

Figure 11 - Targeted services are stopped

The executable stops a list of processes that might interfere with the encryption. The list of all processes can be found in the Appendix.

Figure 12 - Targeted processes are killed

Volume Shadow Copies Deletion

The ransomware deletes all volume shadow copies by calling the CreateVssBackupComponentsInternal function and then DeleteSnapshots on every shadow copy found (see Figure 13).

Figure 13 - Delete volume shadow copies using COM interface

Encryption of Files

GetDriveTypeW is used to retrieve the drive type, which must be different than 0x1 (DRIVE_NO_ROOT_DIR) and 0x5 (DRIVE_CDROM):

Figure 14 - GetDriveTypeW API call

The following files and directories will not be encrypted by Warlock Ransomware:

Figure 15 - Skipped files and directories

The malware creates multiple threads that will handle the file encryption. Firstly, it appends the “.x2anylock” extension to every file to be encrypted using MoveFileW:

Figure 16 - Append the ransomware’s extension to encrypted files

The ransomware uses Curve25519 (CryptoPP library) and ChaCha20 for encrypting files. It calls BCryptGenRandom to generate 32 random bytes (session private key), computes the 32-byte session public key using Curve25519, and then computes the 32-byte shared secret using the session private key and a hard-coded 32-byte public key. The ChaCha20 key is the SHA256 of the shared secret and the IV is equal to the first 8 bytes from the key. The entire workflow is highlighted in the figure below. The threat actor can recover the shared secret using the session public key that is written to the encrypted file and the secret private key that corresponds to the hard-coded public key.

Figure 17 - Generate the shared secret using Curve25519

Figure 18 - Hard-coded 32-byte public key

The ransomware traverses the directories and encrypts the files using ChaCha20:

Figure 19 - Open targeted file for encryption

Figure 20 - Write encrypted content to the file

A snippet of the ChaCha20 implementation is displayed in Figure 21.

Figure 21 - ChaCha20 algorithm

An example of an encrypted file is displayed below. The footer contains the 32-byte session public key generated before and the hard-coded GUID already mentioned.

Figure 22 - Footer contains the 32-byte session public key and GUID

The ransom note called “How to decrypt my data.txt” is dropped in every encrypted directory (Figure 23).

Figure 23 - Ransom note

Warlock Through the Eyes of Hybrid Analysis

The Hybrid Analysis sandbox report reveals multiple key behavioral indicators of Warlock ransomware's functionality. The analysis identifies the ransomware's unique file extension and confirms its use of the ChaCha20 algorithm for file encryption. A significant indicator of malicious intent is the ransomware's systematic termination of backup and AntiVirus software services. The in-depth technical analysis provides crucial evidence from the dynamic analysis and describes the volume shadow copies deletion process, as well as every step of the complex file encryption workflow. 

Hybrid Analysis is a powerful platform for identifying and analyzing malware, whether mundane or highly sophisticated. It provides detailed context and information that can be investigated further during the dynamic analysis of the malware. For performing a more in-depth analysis of malware samples, you can download them by registering with a Hybrid Analysis account and becoming a vetted user.

Indicators of Compromise

SHA256

File created 
How to decrypt my data.txt

Appendix

Targeted processes
"sql.exe", "oracle.exe", "ocssd.exe", "dbsnmp.exe", "synctime.exe", "agntsvc.exe", "isqlplussvc.exe", "xfssvccon.exe", "mydesktopservice.exe", "ocautoupds.exe", "encsvc.exe", "firefox.exe", "tbirdconfig.exe", "mydesktopqos.exe", "ocomm.exe", "dbeng50.exe", "sqbcoreservice.exe", "excel.exe", "infopath.exe", "msaccess.exe", "mspub.exe", "onenote.exe", "outlook.exe", "powerpnt.exe", "steam.exe", "thebat.exe", "thunderbird.exe", "visio.exe", "winword.exe", "wordpad.exe", "notepad.exe"

Targeted services
"vss", "sql", "svc$", "memtas", "mepocs", "sophos", "veeam", "backup", "GxVss", "GxBlr", "GxFWD", "GxCVD", "GxCIMgr", "DefWatch", "ccEvtMgr", "ccSetMgr", "SavRoam", "RTVscan", "QBFCService", "QBIDPService", "Intuit.QuickBooks.FCS", "QBCFMonitorService", "YooBackup", "YooIT", "zhudongfangyu", "sophos", "stc_raw_agent", "VSNAPVSS", "VeeamTransportSvc", "VeeamDeploymentService", "VeeamNFSSvc", "veeam", "PDVFSService", "BackupExecVSSProvider", "BackupExecAgentAccelerator", "BackupExecAgentBrowser", "BackupExecDiveciMediaService", "BackupExecJobEngine", "BackupExecManagementService", "BackupExecRPCService", "AcrSch2Svc", "AcronisAgent", "CASAD2DWebSvc", "CAARCUpdateSvc"

Thursday, July 24, 2025

New Advanced Stealer (SHUYAL) Targets Credentials Across 19 Popular Browsers

 Author(s): Vlad Pasca

  • New advanced stealer analyzed though Hybrid Analysis and named 'SHUYAL' 
  • Hybrid Analysis report reveals the stealer can grab credentials from 19 different web browsers (Chrome, Brave, Edge, Opera, OperaGx, Yandex, Vivaldi, Chromium, Waterfox, Tor, Epic, Comodo, Slimjet, Coccoc, Maxthon, 360browser, Ur, Avast and Falkon)
  • SHUYAL features advanced evasion tactics, featuring self-deletion capabilities and sophisticated anti-detection mechanisms, including automatic Task Manager disablement
  • The stealer employs modern exfiltration methods, combining Discord token theft with Telegram-based data exfiltration 

Hybrid Analysis has analyzed a sophisticated new information stealer that combines extensive credential theft capabilities with advanced system reconnaissance and evasion tactics. Named SHUYAL based on unique identifiers discovered in the executable's PDB path, this previously undocumented stealer demonstrates comprehensive browser targeting, grabbing credentials from 19 different browsers ranging from mainstream applications like Chrome and Edge to privacy-focused options such as Tor.

Analysis shows SHUYAL performing thorough system reconnaissance, gathering detailed information about disk drives, input devices, and display configurations. The malware employs aggressive defense evasion techniques, including the automatic termination and subsequent disabling of Windows Task Manager. Beyond credential theft, SHUYAL captures system screenshots and clipboard content, exfiltrating this data alongside stolen Discord tokens through a Telegram bot infrastructure. The malware maintains operational stealth through self-deletion mechanisms, removing traces of its activity using a batch file after completing its primary functions.

This research presents a detailed technical analysis of SHUYAL, documenting its capabilities and behaviors through comprehensive Hybrid Analysis indicators, combined with in-depth technical analysis of a publicly available sample.

A Hybrid Analysis Perspective

We’ve named this stealer SHUYAL based on the PDB path extracted from the executable. As we can see in the Hybrid Analysis report, the path also reveals the “sheepy” username:

Figure 1 - PDB path extracted in the Hybrid Analysis report

The malware disables Windows Task Manager on the machine by modifying the “DisableTaskMgr” registry value (see Figure 2).

Figure 2 - Disabling Windows Task Manager

The stealer tries to access login credentials from a list of browsers, including Google Chrome, Opera and Microsoft Edge. The entire list will be presented in the technical analysis.

Figure 3 - Multiple browsers are targeted by the stealer

Spawning multiple processes (as highlighted below), SHUYAL retrieves the model and serial number of the available disk drives, information about the keyboard and mouse installed on the machine, and details about the monitor attached to the computer. The last command (“wmic get name”) is incomplete and doesn’t return any useful information.

 Figure 4 - Multiple processes retrieve information about the infected host


Figure 5 from the Hybrid Analysis report reveals that the process uses PowerShell to compress a folder from the “%TEMP%” directory. The folder contains information to be exfiltrated, as we’ll see in the upcoming sections.

Figure 5 - Create an archive to be exfiltrated using PowerShell



The stealer performs data exfiltration via a Telegram bot (Figure 6).

Figure 6 - Data exfiltration occurs via Telegram


The malware is very stealthy because it deletes the newly created files from the browsers’ databases and all files from the “runtime” directory that were previously exfiltrated:

Figure 7 - Malware deletes the created files for stealthiness


The malicious process extracts the path of the Desktop Wallpaper using PowerShell, as shown in the figure below.

Figure 8 - Extract the path of the Desktop Wallpaper


A Deeper Dive into SHUYAL

The binary creates an anonymous pipe via a call to CreatePipe. The pipe will be used to read the output of the processes to be spawned:

Figure 9 - CreatePipe API call


Reconnaissance

The stealer performs reconnaissance by creating multiple processes:

  • wmic diskdrive get model,serialnumber (retrieve the model and serial number of the available disk drives)
  • wmic path Win32_Keyboard get Description,DeviceID (retrieve information about the keyboard)
  • wmic path Win32_PointingDevice get Description,PNPDeviceID (created twice, retrieve information about the mouse)
  • wmic path Win32_DesktopMonitor get Description,PNPDeviceID (retrieve details about the monitor attached to the computer)
  • wmic get name (returns an error)
  • powershell -command “(Get-ItemProperty 'HKCU:\Control Panel\Desktop').Wallpaper” (retrieve the path of the Desktop Wallpaper)

Figure 10 - Obtain information about the machine

The malware enumerates the running processes looking for the Task Manager process. If found, it is killed by calling the TerminateProcess method (see Figure 11).

Figure 11 - Task Manager process is stopped


The process disables Task Manager by modifying the “DisableTaskMgr” registry value to 1, as highlighted below:

Figure 12 - Disable Task Manager by modifying a registry value


Persistence

SHUYAL obtains the user’s Startup folder using the SHGetSpecialFolderPathA API (0x7 = CSIDL_STARTUP):

Figure 13 - SHGetSpecialFolderPathA API call


The malware establishes persistence by self-copying to the Startup folder via a function call to CopyFileA. We can also observe the strings that appear in the code, confirming the success/failure of the operation.

Figure 14 - Copy operation to the Startup folder


The stealer obtains a handle to the standard output device and adds the ENABLE_ECHO_INPUT mode to the output mode:

Figure 15 - Modify the console mode


Data stealing

SHUYAL attempts to locate the “Login Data” file, which stores login data (including usernames and URLs), for the following browsers: Chrome, Brave, Edge, Opera, OperaGx, Yandex, Vivaldi, Chromium, Waterfox, Tor, Epic, Comodo, Slimjet, Coccoc, Maxthon, 360browser, Ur, Avast and Falkon.

Figure 16 - GetFileAttributesExW API call


The identified files are copied to the current directory of the malware. For example, the file corresponding to Chrome is copied as “chrome_Data.db” (Figure 17).

Figure 17 - Copy targeted databases to the current directory


The following SQL query is executed, "SELECT origin_url, username_value, password_value FROM logins". The encrypted passwords will be decrypted and stored in a newly created file called “saved_passwords.txt” found in the “runtime” directory created in the temporary folder. The decryption works by extracting the Master key from the “Local State” file, base64-decode the key, and then decrypt it using the DPAPI CryptUnprotectData. The Master key can be used to decrypt the browser credentials. The browsing history is extracted from “\User Data\Default\History” and saved as “history.txt” in the same directory. Figure 18 presents the SQL query that is executed:

Figure 18 - SQL query execution


The process extracts data from the clipboard using the OpenClipboard and GetClipboardData functions. It is saved in a file called “clipboard.txt”:

Figure 19 - Extract data from the clipboard



Figure 20 - Data is saved in a file called clipboard.txt

The stealer takes a screenshot using the GdiplusStartup, BitBlt, and GdipSaveImageToFile APIs, and saves it in a file called “ss.png”:

Figure 21 - APIs used to take the screenshot


Figure 22 - GdipSaveImageToFile function call

It also steals tokens from Discord, Discord Canary, and Discord PTB (Figure 23).

Figure 23 - Malware steals tokens from Discord applications


The malware creates a log file called “debug_log.txt” that contains information about the targeted browsers and other applications:

Figure 24 - Content of the log file


Data exfiltration

The malicious executable compresses the “runtime” directory containing files to be exfiltrated to an archive called “runtime.zip” using PowerShell, as shown in the figure below.

Figure 25 - Folder to be exfiltrated is compressed to an archive


The archive is exfiltrated to the following Telegram bot:

Figure 26 - Telegram bot


WSAEnumNetworkEvents is utilized to discover occurrences of network events for a socket:

Figure 27 - WSAEnumNetworkEvents API call


After finishing the malicious activity, the stealer performs self-deletion using a batch file called “util.bat”:

Figure 28 - Content of the self-deletion batch script


Figure 29 - Execution of the newly created batch file

SHUYAL Through the Eyes of Hybrid Analysis

The Hybrid Analysis report identifies multiple behavioral patterns and indicators that clearly classify SHUYAL as a new,  information-stealing malware. For example, it highlights that the sample obtains login credentials from a list of browsers, including Google Chrome, Opera, Edge and others. Our in-depth technical analysis extends beyond behavioral observations to examine SHUYAL's core functionality, enabling the development of more effective detection and defense mechanisms.

Hybrid Analysis is a powerful platform for identifying and analyzing malware, whether mundane or highly sophisticated. It provides detailed context and information that can be investigated further during the dynamic analysis of the malware. For performing a more in-depth analysis of malware samples, you can download them by registering with a Hybrid Analysis account and becoming a vetted user.

Indicators of Compromise

SHA256


Files created

C:\Users\<User>\AppData\Local\Temp\runtime\browser\debug_log.txt
C:\Users\<User>\AppData\Local\Temp\runtime\browser\tokens.txt
C:\Users\<User>\AppData\Local\Temp\runtime\clipboard\clipboard.txt
C:\Users\<User>\AppData\Local\Temp\runtime\history\history.txt
C:\Users\<User>\AppData\Local\Temp\runtime\passwords\saved_passwords.txt
C:\Users\<User>\AppData\Local\Temp\runtime\pic\ss.png
C:\Users\<User>\AppData\Local\Temp\runtime.zip
util.bat


Processes spawned

wmic diskdrive get model,serialnumber
wmic path Win32_Keyboard get Description,DeviceID
wmic path Win32_PointingDevice get Description,PNPDeviceID
wmic path Win32_DesktopMonitor get Description,PNPDeviceID
wmic get name
powershell -command "(Get-ItemProperty 'HKCU:\Control Panel\Desktop').Wallpaper”
powershell -Command “Compress-Archive -Path ‘C:\Users\<User>\AppData\Local\Temp\runtime\*’ -DestinationPath ‘C:\Users\<User>\AppData\Local\Temp\runtime.zip’ -Force


Telegram Bot

hxxps[:]//api.telegram[.]org/bot7522684505:AAEODeii83B_nlpLi0bUQTnOtVdjc8yHfjQ/sendDocument?chat_id=-1002503889864