At a Glance
| Actor | Longlegs (Symantec), also tracked as Storm-2603; described as China-nexus |
| Activity | SharePoint exploitation, security tool disabling, Warlock ransomware deployment |
| Targets | A water utility, a telecom provider, a regional government body, and a university |
| Scale | At least four organizations in the past two months (Symantec); victims not named |
| Law enforcement | No arrests or charges announced |
| Sources | Symantec Threat Hunter Team; ReliaQuest |
TL;DR
A China-linked group hit four organizations in Portuguese- and Spanish-speaking countries over two months. It entered through SharePoint flaws, disabled security tools with a vulnerable driver, and spread Warlock across whole networks. Two of the victims run critical infrastructure.
What Happened
SharePoint Remains the Way In
Warlock first made headlines in July 2025. At that time, its operators exploited the “ToolShell” zero-day chain in on-premises SharePoint. A year later, those SharePoint vulnerabilities still work against unpatched servers. Symantec says the group also uses newer SharePoint bugs that CISA warned about in July 2026.
Once inside, the attackers drop a web shell into several SharePoint version folders at once. That way, it works no matter which version is installed. The web shell steals the server’s ASP.NET machine keys. With those keys, the attackers forge signed requests that run code on the server.
One Intrusion, Step by Step
Symantec traced one attack on a critical infrastructure operator. It began on July 22 with a web shell on a SharePoint server. Over the next week, the attackers ran reconnaissance and tested their access. Then they pulled extra payloads from public file-hosting and cloud storage services. Using several services, Symantec notes, meant they “were not relying on a single point of delivery.”
Next, they added a fake SharePoint-style account to the local admin group on more hosts. On one machine, they abused Visual Studio Code’s built-in tunnel feature for remote access. Because Microsoft signs the binary and relays the traffic, it “can blend more easily” into normal admin activity. The open-source NetExec tool then helped them map and spray credentials across the domain.
Killing Defenses, Then Encrypting
The final phase came early on July 31. The attackers pushed a security-killing tool to at least 40 hosts in about two hours. In other attacks, the group has used K7RKScan, a signed but flawed driver tracked as CVE-2025-1055. This “bring your own vulnerable driver” trick lets them stop security software at the kernel level.
Warlock appeared almost as soon as protection dropped. The attackers staged it in the domain’s SYSVOL share, which Windows copies to every domain controller. Normal replication then carried the ransomware to at least 33 hosts.
Who Is Behind It
Symantec says a China-nexus group it calls Longlegs develops Warlock. Microsoft tracks the same actor as Storm-2603. Symantec also links the group to older clusters, including CamoFei and ChamelGang. This is a vendor assessment. No government has charged anyone over these attacks.
Other researchers have seen the group branch out. In February 2026, ReliaQuest tied Storm-2603 to attacks on SmarterMail servers through CVE-2026-23760. It made that link with “moderate-to-high confidence.” So SharePoint is the favorite door, but not the only one.
Impact and Scale
Symantec counts at least four victims in the past two months. They sit in Portuguese- and Spanish-speaking countries across Europe, Africa, and Latin America. Earlier Warlock attacks hit the US, Brazil, India, Russia, Taiwan, and Japan.
Symantec does not say whether the recent focus is deliberate. It may simply reflect where exposed SharePoint servers sit. Either way, the firm warns of “potential real-world consequences” when ransomware hits essential services. No ransom amounts or data leaks have been reported.
How to Stay Protected
The Warlock ransomware playbook relies on known flaws and common admin tools. Defenders can take these steps:
- Patch on-premises SharePoint for ToolShell and the newer flaws in CISA’s July 2026 advisory.
- Rotate SharePoint ASP.NET machine keys after patching, since stolen keys still work.
- Block known vulnerable drivers, including K7RKScan, with Microsoft’s driver blocklist.
- Alert on new executables in SYSVOL scripts folders.
- Watch for VS Code tunnels running as services on servers.
- Flag new local admin accounts that mimic SharePoint service names.
Finally, keep offline backups and test them. If the attackers reach SYSVOL, they can reach every machine on the domain.
Support Our Threat Intelligence
Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!