Warlock Ransomware Group Hits Water and Telecom Operators, Continues Exploiting SharePoint

Summary
Symantec attributes recent attacks on at least four organizations to Longlegs, which it tracks as Storm-2603. The group exploited SharePoint, disabled security tools and deployed Warlock ransomware across victim networks.
Key points
- Symantec links Warlock ransomware to the China-nexus group Longlegs, also known as Storm-2603.
- In the past two months, the group attacked at least four organizations in Portuguese- and Spanish-speaking countries: a water utility, a telecom provider, a regional government body and a university.
- The group gains access through vulnerabilities in on-premises SharePoint, using a webshell to obtain machine keys and forge signed payloads for remote code execution.
- Attackers used DLL sideloading, legitimate file-hosting services and Visual Studio Code tunnels for payload delivery and covert access.
- In one intrusion, a tool likely using a vulnerable driver was used to disable security software on at least 40 hosts; Warlock was then deployed on at least 33.
- The ransomware was staged in SYSVOL, allowing domain replication to distribute it across the victim's network.
- Symantec says SharePoint flaws used by the group remain a viable entry route where systems are unpatched or otherwise unmitigated.
Article Details
- Attack Vectors
- Longlegs typically gains initial access by exploiting vulnerabilities in on-premises Microsoft SharePoint Server. In the detailed intrusion, SharePoint exploitation was assessed as the likely initial vector.
- The group places a webshell in SharePoint LAYOUTS directories for multiple versions, harvests ASP.NET machine keys, and uses a forged, validly signed __VIEWSTATE payload to execute code in the SharePoint application pool.
- The attackers used DLL side-loading and downloaded follow-on MSI packages from specific resources on cloud file-sharing and storage services.
- The attackers added the domain account SPSEPRDSetup to local Administrators groups, used NetExec for domain activity, and installed a Visual Studio Code tunnel service for remote access.
- In the detailed intrusion, an AV/EDR-killing tool ran on at least 40 further hosts within about two hours. The vulnerable driver used in that intrusion was not identified; the group has used K7RKScan in other recent attacks.
- The attackers staged Warlock payloads in the compromised domain's SYSVOL share. SYSVOL replication delivered the payloads to hosts, and ransomware binaries and a ransom note were recorded on at least 33 hosts.
- Defensive Notes
- Patch or otherwise mitigate vulnerable Microsoft SharePoint Server deployments; the article identifies continued SharePoint exploitation as an initial-access risk.
- Investigate unexpected webshells in SharePoint LAYOUTS directories, anomalous use of administrative commands, unauthorized local Administrators group changes, and unexpected Visual Studio Code tunnel services.
- Monitor for security-process termination associated with vulnerable drivers and for ransomware payloads staged in SYSVOL. Symantec says Symantec CBX can flag anomalous living-off-the-land activity and help analysts trace an attack before domain-wide deployment.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| HOSTNAME | litter[.]catbox[.]moe | Listed as a network IOC; its payload URL was used to fetch an MSI package. |
| HOSTNAME | xn8xyt-drop[.]s3[.]wasabisys[.]com | Listed as a network IOC; its payload URL was used to fetch an MSI package. |
| SHA256 | 116ca4e88a1bcebb6c0da7fb431c8eca7b8ef3f9767194820c56091972ccac2c | File indicator identified as Warlock. |
| SHA256 | 155fb1cbdaea12c83ba92d18c88cf38bbc42bb684f913ca0bc26fcf115426a55 | File indicator identified as Warlock. |
| SHA256 | 1edb2c0b537cd95bbd5fc16321b4c38a6adf325ccc7b588ad6acc980b0463b60 | File indicator identified as a malicious DLL. |
| SHA256 | 206f27ae820783b7755bca89f83a0fe096dbb510018dd65b63fc80bd20c03261 | File indicator identified as a malicious DLL. |
| SHA256 | 27b7591cf9e1283010ca98fa5dbe970a73fee0d8cde277639924c144718db7c0 | File indicator identified as a malicious DLL. |
| SHA256 | 37f94fe1b4a106f02b6f74a69cbc05e69c17406f688beef4c9a045ffcbd2e65e | File indicator identified as a suspicious file. |
| SHA256 | 6d07f1232dc59b84038fd0b2e75fdd3d5b825882bb0dba9e6724b7b0823fa3ad | File indicator identified as Warlock. |
| SHA256 | 73c5268256c9da5488cd9e2b79013060ac321c7e54129344dc7b51e268af36ea | File indicator identified as an AV/EDR killer. |
| SHA256 | 8b58f7811a2a2f2a5024220490473774f02759dd2dd904b5b9fabfbaae37125f | File indicator identified as Warlock. |
| SHA256 | 8ce8d8270ee9de02644530b8dd7fa78973b4a3b80f121e2c5f45ae68cce196f9 | File indicator identified as Warlock. |
| SHA256 | 9ceb01f8bf7d6dba2ae07f5bd6070de3ec67b5eb01f969b0ba85e74564fb83a7 | File indicator identified as a suspicious file. |
| SHA256 | aaff04d84ef85353966aa4af186ff1254b72c068f33f802417b29dc23fb9f192 | File indicator identified as a suspicious file. |
| SHA256 | ae9f7fce57c7b928e659dccf0e00fa79cd9cd61a106f18d4e03f92dc3a03c295 | File indicator identified as a vulnerable driver. |
| SHA256 | c46825fcc0d1bf7a8b192facb176d6bf916c9dccfd6fa994be691e3b0e585f4e | File indicator identified as a malicious DLL. |
| SHA256 | e14240bac8277b0f6dd4d29ab5da20d246bcccae647e5fe8d19cdae7fe471b20 | File indicator identified as a malicious DLL. |
| SHA256 | e3204b05e2f3a29bb6e6fcc21dda77d7cd31dfa755c21da0aa8661b5619ee0a1 | File indicator identified as a suspicious file. |
| SHA256 | eea631b5f7125239db0811e4682c2316ead69f9822e02d94fb5d8bf0d2faebed | File indicator identified as a suspicious file. |
| SHA256 | f7269f80f81e99d06a590d7ab374e12fdf7e5f55a02c2a46c342d670f8519fdf | File indicator identified as a suspicious file. |
| SHA256 | fb3846c9ac53d1b841ada3a6b1091153fea41a169cb44fe0084097d1f4d45984 | File indicator identified as a malicious DLL. |
| URL | hxxps[:]//litter[.]catbox[.]moe/6f5tdt[.]msi | Specific MSI payload URL fetched by the attackers. |
| URL | hxxps[:]//s3[.]wasabisys[.]com/fortifs/vamd64[.]msi | Specific MSI payload URL fetched by the attackers. |
| URL | hxxps[:]//xn8xyt-drop[.]s3[.]wasabisys[.]com/xn8xyt[.]msi | Specific MSI payload URL fetched by the attackers. |
MITRE ATT&CK
T1059.001 · PowerShellThe attackers ran PowerShell to write an ASPX webshell and used PowerShell commands during the intrusion.T1087.002 · Domain AccountThe attackers ran net user /domain during reconnaissance.T1098.007 · Additional Local or Domain GroupsThe attackers repeatedly added the domain account SPSEPRDSetup to local Administrators groups on additional hosts.T1105 · Ingress Tool TransferThe attackers fetched follow-on MSI payloads from external URLs using msiexec.T1110.003 · Password SprayingThe article reports that the attackers used NetExec for credential spraying.T1190 · Exploit Public-Facing ApplicationLonglegs exploits vulnerabilities in on-premises Microsoft SharePoint Server for initial access.T1219 · Remote Access ToolsThe attackers installed Visual Studio Code's built-in tunnel feature as a service for covert remote access.T1482 · Domain Trust DiscoveryThe attackers ran nltest /domain_trusts to enumerate the victim's Active Directory domain trust relationships.T1505.003 · Web ShellThe attackers installed a webshell in a SharePoint LAYOUTS directory.T1543.003 · Windows ServiceThe attackers ran code-insiders.exe tunnel service install to establish a remote-access service.T1562.001 · Disable or Modify ToolsBefore ransomware deployment, the attackers pushed an AV/EDR-killing tool across hosts; the group has also used the vulnerable K7RKScan driver to terminate protected security processes.T1570 · Lateral Tool TransferThe attackers staged ransomware binaries in SYSVOL, and ordinary domain replication delivered them to additional hosts.T1574.002 · DLL Side-LoadingThe attackers deployed DLLs alongside executables in apparent DLL side-loading pairs.
CVE
CVE-2025-1055software ahead of deploying ransomware, Longlegs abuses K7RKScan, a signed but vulnerable driver (CVE-2025-1055) that can be used to terminate protected security processes at the kernel level, a clear example ofCVE-2025-49704it were found exploiting zero-day vulnerabilities in Microsoft SharePoint Server, dubbed "ToolShell" (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771). Those flaws likely remain in the group'sCVE-2025-49706zero-day vulnerabilities in Microsoft SharePoint Server, dubbed "ToolShell" (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771). Those flaws likely remain in the group's arsenal, alongsideCVE-2025-53770vulnerabilities in Microsoft SharePoint Server, dubbed "ToolShell" (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771). Those flaws likely remain in the group's arsenal, alongside newer SharePointCVE-2025-53771Microsoft SharePoint Server, dubbed "ToolShell" (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771). Those flaws likely remain in the group's arsenal, alongside newer SharePoint flaws, which the U.S.
Threat Actors
CamoFeiAn older activity cluster that Symantec previously tied to Longlegs; the article does not explicitly call it an alias.ChamelGangAn older activity cluster that Symantec previously tied to Longlegs; the article does not explicitly call it an alias.CL-CRI-1040An older activity cluster that Symantec previously tied to Longlegs; the article does not explicitly call it an alias.LonglegsSymantec's name for the China-nexus group behind Warlock; the article identifies Storm-2603 as an alias and ties the group to older activity clusters.Storm-2603Identified in the article as an alias of Longlegs.
Malware
Vendors
MicrosoftWarlock first came to prominence via the exploitation of a Microsoft SharePoint “ToolShell” exploit chain.SymantecWarlock is developed by a China-nexus threat actor Symantec calls Longlegs (aka Storm-2603). Symantec has previously tied this group to older activity clusters known as CL-CRI-1040, CamoFei, and ChamelGang.
Products
Microsoft SharePoint Serverweeks later, when attackers deploying it were found exploiting zero-day vulnerabilities in Microsoft SharePoint Server, dubbed "ToolShell" (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771). ThoseSymantec CBXSymantec CBX, our unified XDR platform, provides multiple layers of defense against attacks like this. Its Adaptive Protection capability can automatically flag and block anomalous use of legitimate living-off-the-landVisual Studio CodeLonglegs abuses a vulnerable, signed driver (K7RKScan) to disable security software before deploying ransomware, and has also been observed abusing Visual Studio Code's tunneling feature for covert remote access.
Tools
Burp CollaboratorThree days later, on July 27, Computer 2 issued an outbound web request to a subdomain of oastify.com, the domain used by vulnerability detection service Burp Collaborator for out-of-band interaction testing:K7RKScanLonglegs abuses a vulnerable, signed driver (K7RKScan) to disable security software before deploying ransomware, and has also been observed abusing Visual Studio Code's tunneling feature for covert remote access.NetExecLater that evening Computer 2 ran NetExec (nxc.exe), the open-source, actively maintained successor to the CrackMapExec penetration testing framework. It was used for Active Directory enumeration, credential spraying,
Countries
Brazilbeen observed against organizations in a wider range of countries, including the United States, Brazil, India, Russia, Taiwan, and Japan.Indiabeen observed against organizations in a wider range of countries, including the United States, Brazil, India, Russia, Taiwan, and Japan.Japanin a wider range of countries, including the United States, Brazil, India, Russia, Taiwan, and Japan.Russiaobserved against organizations in a wider range of countries, including the United States, Brazil, India, Russia, Taiwan, and Japan.Taiwanagainst organizations in a wider range of countries, including the United States, Brazil, India, Russia, Taiwan, and Japan.United Stateshas previously been observed against organizations in a wider range of countries, including the United States, Brazil, India, Russia, Taiwan, and Japan.
Industries
Educationin Portuguese and Spanish-speaking countries, hitting critical infrastructure, government, and education organizations.Governmentattacking organizations in Portuguese and Spanish-speaking countries, hitting critical infrastructure, government, and education organizations.Telecommunicationsat least four organizations, including two critical infrastructure operators (a water utility and a telecommunications provider), a regional government body, and a university. Victims were in Portuguese- andWater utilities