A China-nexus threat actor is continuing to exploit Microsoft SharePoint Server weaknesses to deploy Warlock ransomware, with recent victims spanning essential services and public institutions. Symantec tracks the operator as Longlegs, while Microsoft calls it Storm-2603. The latest activity affected at least four organizations over two months, including a water utility, a telecommunications provider, a regional government body and a university.
The incidents reached organizations across Europe, Africa and Latin America, particularly in Portuguese- and Spanish-speaking environments. Although the selection of victims could reflect deliberate regional targeting or simply the availability of exposed servers, the operational result is the same: a vulnerable collaboration platform can provide attackers with a route into identity infrastructure and business-critical systems.
From ToolShell exploitation to persistent access
Warlock emerged in 2025 after attackers began using the SharePoint exploit chain commonly called ToolShell. That chain combined CVE-2025-49704 and CVE-2025-49706, followed by bypasses tracked as CVE-2025-53770 and CVE-2025-53771. CISA warned that exploitation could expose internal configuration data and enable remote code execution on supported on-premises SharePoint editions.
In the newer operations, Longlegs typically places an ASPX web shell in SharePoint’s LAYOUTS directory. The implant extracts ASP.NET machine keys, which can let the intruders forge signed __VIEWSTATE data and execute code in the SharePoint application pool. That capability is especially dangerous because removing the first visible web shell may not invalidate the cryptographic material already stolen by the attacker.
The group then uses DLL sideloading to run additional malware. Installers have been delivered from legitimate hosting providers such as Catbox and Wasabi, allowing downloads to blend with traffic that may not immediately look hostile. This combination of a public-facing exploit, trusted cloud infrastructure and signed software complicates simple allow-list-based defenses.
Attackers move from one server to the domain
One critical-infrastructure intrusion began with a SharePoint web shell on July 22, 2026. The attackers issued common discovery commands, mapped domain relationships and used NetExec for Active Directory reconnaissance, credential spraying and remote execution. They also installed Microsoft’s signed code-insiders.exe as a service and abused Visual Studio Code tunneling to maintain covert remote access.
Before launching encryption, the operators distributed a utility designed to terminate antivirus and endpoint-detection processes to at least 40 machines in roughly two hours. Recent Longlegs activity has used a signed but vulnerable K7 security driver affected by CVE-2025-1055, a bring-your-own-vulnerable-driver technique that can shut down privileged defenses from kernel space. Investigators did not conclusively identify the exact driver in this particular intrusion, so defenders should avoid overstating that detail.
Trusted replication spreads the ransomware
Warlock followed quickly on at least 33 systems. The operators placed executables and a ransom note in the compromised domain’s SYSVOL share. Because SYSVOL is broadly readable and replicated between domain controllers, normal Distributed File System Replication helped propagate the attack materials. Infrastructure intended to keep policy data consistent effectively became a distribution mechanism.
This sequence shows why patching an exposed SharePoint host is necessary but insufficient after suspected exploitation. Defenders should assume attackers may have harvested secrets, created alternate access paths or reached Active Directory before the server was updated.
- Hunt for web shells and abnormal SharePoint worker-process activity.
- Rotate ASP.NET and IIS machine keys after persistence is removed.
- Review service creation, VS Code tunnels and unusual SYSVOL files.
- Keep Central Administration off the public internet and place required access behind an authenticated application proxy.
- Test recovery plans for domain services and operational technology dependencies.
Containment requires identity and recovery work
Organizations should isolate suspected servers, preserve forensic evidence and review the complete path from SharePoint to domain administration. Credential resets must include service and machine secrets where appropriate, while endpoint teams should investigate defense-tampering across every reachable host. The Cyber Security News report also lists file hashes and delivery domains for targeted hunting.
For water, telecom, government and education operators, the case is a reminder that perimeter software and internal identity systems cannot be triaged separately. One internet-facing collaboration server can become the first step toward widespread encryption and operational disruption if defenders close the vulnerability without removing the attacker’s foothold.
Leave a Reply
You must be logged in to post a comment.