Warlock Ransomware Group Hits Water and Telecom Operators, Continues Exploiting SharePoint

· Original article ↗

Summary

Symantec attributes recent attacks on at least four organizations to Longlegs, which it tracks as Storm-2603. The group exploited SharePoint, disabled security tools and deployed Warlock ransomware across victim networks.

Key points

  • Symantec links Warlock ransomware to the China-nexus group Longlegs, also known as Storm-2603.
  • In the past two months, the group attacked at least four organizations in Portuguese- and Spanish-speaking countries: a water utility, a telecom provider, a regional government body and a university.
  • The group gains access through vulnerabilities in on-premises SharePoint, using a webshell to obtain machine keys and forge signed payloads for remote code execution.
  • Attackers used DLL sideloading, legitimate file-hosting services and Visual Studio Code tunnels for payload delivery and covert access.
  • In one intrusion, a tool likely using a vulnerable driver was used to disable security software on at least 40 hosts; Warlock was then deployed on at least 33.
  • The ransomware was staged in SYSVOL, allowing domain replication to distribute it across the victim's network.
  • Symantec says SharePoint flaws used by the group remain a viable entry route where systems are unpatched or otherwise unmitigated.

Article Details

Attack Vectors
  • Longlegs typically gains initial access by exploiting vulnerabilities in on-premises Microsoft SharePoint Server. In the detailed intrusion, SharePoint exploitation was assessed as the likely initial vector.
  • The group places a webshell in SharePoint LAYOUTS directories for multiple versions, harvests ASP.NET machine keys, and uses a forged, validly signed __VIEWSTATE payload to execute code in the SharePoint application pool.
  • The attackers used DLL side-loading and downloaded follow-on MSI packages from specific resources on cloud file-sharing and storage services.
  • The attackers added the domain account SPSEPRDSetup to local Administrators groups, used NetExec for domain activity, and installed a Visual Studio Code tunnel service for remote access.
  • In the detailed intrusion, an AV/EDR-killing tool ran on at least 40 further hosts within about two hours. The vulnerable driver used in that intrusion was not identified; the group has used K7RKScan in other recent attacks.
  • The attackers staged Warlock payloads in the compromised domain's SYSVOL share. SYSVOL replication delivered the payloads to hosts, and ransomware binaries and a ransom note were recorded on at least 33 hosts.
Defensive Notes
  • Patch or otherwise mitigate vulnerable Microsoft SharePoint Server deployments; the article identifies continued SharePoint exploitation as an initial-access risk.
  • Investigate unexpected webshells in SharePoint LAYOUTS directories, anomalous use of administrative commands, unauthorized local Administrators group changes, and unexpected Visual Studio Code tunnel services.
  • Monitor for security-process termination associated with vulnerable drivers and for ransomware payloads staged in SYSVOL. Symantec says Symantec CBX can flag anomalous living-off-the-land activity and help analysts trace an attack before domain-wide deployment.

Indicators of compromise

TypeIndicatorContext
HOSTNAMElitter[.]catbox[.]moeListed as a network IOC; its payload URL was used to fetch an MSI package.
HOSTNAMExn8xyt-drop[.]s3[.]wasabisys[.]comListed as a network IOC; its payload URL was used to fetch an MSI package.
SHA256116ca4e88a1bcebb6c0da7fb431c8eca7b8ef3f9767194820c56091972ccac2cFile indicator identified as Warlock.
SHA256155fb1cbdaea12c83ba92d18c88cf38bbc42bb684f913ca0bc26fcf115426a55File indicator identified as Warlock.
SHA2561edb2c0b537cd95bbd5fc16321b4c38a6adf325ccc7b588ad6acc980b0463b60File indicator identified as a malicious DLL.
SHA256206f27ae820783b7755bca89f83a0fe096dbb510018dd65b63fc80bd20c03261File indicator identified as a malicious DLL.
SHA25627b7591cf9e1283010ca98fa5dbe970a73fee0d8cde277639924c144718db7c0File indicator identified as a malicious DLL.
SHA25637f94fe1b4a106f02b6f74a69cbc05e69c17406f688beef4c9a045ffcbd2e65eFile indicator identified as a suspicious file.
SHA2566d07f1232dc59b84038fd0b2e75fdd3d5b825882bb0dba9e6724b7b0823fa3adFile indicator identified as Warlock.
SHA25673c5268256c9da5488cd9e2b79013060ac321c7e54129344dc7b51e268af36eaFile indicator identified as an AV/EDR killer.
SHA2568b58f7811a2a2f2a5024220490473774f02759dd2dd904b5b9fabfbaae37125fFile indicator identified as Warlock.
SHA2568ce8d8270ee9de02644530b8dd7fa78973b4a3b80f121e2c5f45ae68cce196f9File indicator identified as Warlock.
SHA2569ceb01f8bf7d6dba2ae07f5bd6070de3ec67b5eb01f969b0ba85e74564fb83a7File indicator identified as a suspicious file.
SHA256aaff04d84ef85353966aa4af186ff1254b72c068f33f802417b29dc23fb9f192File indicator identified as a suspicious file.
SHA256ae9f7fce57c7b928e659dccf0e00fa79cd9cd61a106f18d4e03f92dc3a03c295File indicator identified as a vulnerable driver.
SHA256c46825fcc0d1bf7a8b192facb176d6bf916c9dccfd6fa994be691e3b0e585f4eFile indicator identified as a malicious DLL.
SHA256e14240bac8277b0f6dd4d29ab5da20d246bcccae647e5fe8d19cdae7fe471b20File indicator identified as a malicious DLL.
SHA256e3204b05e2f3a29bb6e6fcc21dda77d7cd31dfa755c21da0aa8661b5619ee0a1File indicator identified as a suspicious file.
SHA256eea631b5f7125239db0811e4682c2316ead69f9822e02d94fb5d8bf0d2faebedFile indicator identified as a suspicious file.
SHA256f7269f80f81e99d06a590d7ab374e12fdf7e5f55a02c2a46c342d670f8519fdfFile indicator identified as a suspicious file.
SHA256fb3846c9ac53d1b841ada3a6b1091153fea41a169cb44fe0084097d1f4d45984File indicator identified as a malicious DLL.
URLhxxps[:]//litter[.]catbox[.]moe/6f5tdt[.]msiSpecific MSI payload URL fetched by the attackers.
URLhxxps[:]//s3[.]wasabisys[.]com/fortifs/vamd64[.]msiSpecific MSI payload URL fetched by the attackers.
URLhxxps[:]//xn8xyt-drop[.]s3[.]wasabisys[.]com/xn8xyt[.]msiSpecific MSI payload URL fetched by the attackers.

MITRE ATT&CK

T1059.001 · PowerShellThe attackers ran PowerShell to write an ASPX webshell and used PowerShell commands during the intrusion.T1087.002 · Domain AccountThe attackers ran net user /domain during reconnaissance.T1098.007 · Additional Local or Domain GroupsThe attackers repeatedly added the domain account SPSEPRDSetup to local Administrators groups on additional hosts.T1105 · Ingress Tool TransferThe attackers fetched follow-on MSI payloads from external URLs using msiexec.T1110.003 · Password SprayingThe article reports that the attackers used NetExec for credential spraying.T1190 · Exploit Public-Facing ApplicationLonglegs exploits vulnerabilities in on-premises Microsoft SharePoint Server for initial access.T1219 · Remote Access ToolsThe attackers installed Visual Studio Code's built-in tunnel feature as a service for covert remote access.T1482 · Domain Trust DiscoveryThe attackers ran nltest /domain_trusts to enumerate the victim's Active Directory domain trust relationships.T1505.003 · Web ShellThe attackers installed a webshell in a SharePoint LAYOUTS directory.T1543.003 · Windows ServiceThe attackers ran code-insiders.exe tunnel service install to establish a remote-access service.T1562.001 · Disable or Modify ToolsBefore ransomware deployment, the attackers pushed an AV/EDR-killing tool across hosts; the group has also used the vulnerable K7RKScan driver to terminate protected security processes.T1570 · Lateral Tool TransferThe attackers staged ransomware binaries in SYSVOL, and ordinary domain replication delivered them to additional hosts.T1574.002 · DLL Side-LoadingThe attackers deployed DLLs alongside executables in apparent DLL side-loading pairs.

CVE

Threat Actors

Malware

Vendors

Products

Tools

Countries

Industries

Related Articles