Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Chinese Hackers Impersonate Anthropic Employee to Target US AI Policy Experts
October 1, 2026
Critical Microsoft Defender Flaw Lets Attackers Hide Malware
October 1, 2026
WordPress Malware Returns With Self-Healing Backdoor
October 1, 2026
Home/CyberSecurity News/Warlock Ransomware Exploits Critical SharePoint Flaws in Water, Telecom Attacks
CyberSecurity News

Warlock Ransomware Exploits Critical SharePoint Flaws in Water, Telecom Attacks

Key Takeaways A China-linked threat actor, known as Longlegs or Storm-2603, is actively exploiting critical vulnerabilities in Microsoft SharePoint Server. The campaign targets essential service...

David kimber
David kimber
October 1, 2026 4 Min Read
2 0

Key Takeaways

  • A China-linked threat actor, known as Longlegs or Storm-2603, is actively exploiting critical vulnerabilities in Microsoft SharePoint Server.
  • The campaign targets essential service providers and public sector organizations, including water utilities, telecommunications companies, government bodies, and universities.
  • Warlock ransomware is the primary payload, impacting organizations across Europe, Africa, and Latin America.
  • The attacks leverage a sophisticated “ToolShell” exploit chain and subsequent bypasses, along with a vulnerable driver (CVE-2025-1055) to disable security software.
  • Defenders must implement comprehensive strategies beyond patching, focusing on webshell detection, key rotation, and network segmentation to mitigate risks.

A sophisticated threat actor, believed to be operating from China, continues to leverage critical vulnerabilities within Microsoft SharePoint Server to deploy Warlock ransomware. Recent operations have targeted vital infrastructure and public sector entities in Portuguese- and Spanish-speaking regions.

Table Of Content

  • Key Takeaways
  • Warlock Ransomware Exploiting SharePoint Flaws
  • File Indicators
  • Network Indicators
  • What You Should Do

Security researchers at Symantec identify this group as Longlegs, while Microsoft tracks them under the designation Storm-2603. The group’s past activities have also been associated with other aliases, including CL-CRI-1040, CamoFei, and ChamelGang.

Over the past two months, this campaign has successfully breached at least four distinct organizations: a water utility, a telecommunications provider, a regional government agency, and an academic institution. These attacks have spanned geographical locations across Europe, Africa, and Latin America, highlighting the global reach and indiscriminate nature of the threat.

Warlock Ransomware Exploiting SharePoint Flaws

Warlock ransomware first emerged in June 2025, quickly gaining notoriety for its deployment via the “ToolShell” exploit chain in SharePoint. This initial chain leveraged a combination of vulnerabilities, specifically CVE-2025-49704 and CVE-2025-49706. Subsequent bypasses to these exploits were later identified and assigned CVE-2025-53770 and CVE-2025-53771.

The Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that this exploit chain facilitates unauthorized access to on-premises SharePoint servers, leading to the exposure of internal configurations and enabling remote code execution. Warlock ransomware was frequently observed as the final payload on systems compromised through these vulnerabilities. Even with the disclosure of newer SharePoint flaws in 2026, the attack surface remains significant, with CISA issuing warnings about active exploitation affecting supported on-premises editions.

According to research published by Symantec, the Longlegs group typically establishes persistence by planting an ASPX webshell within SharePoint’s LAYOUTS directory. This tactic often targets multiple SharePoint product versions concurrently.

Once deployed, the webshell is designed to extract ASP.NET machine keys. This critical step enables the attackers to forge signed __VIEWSTATE payloads, allowing them to execute arbitrary code directly within the SharePoint application pool. Subsequent malware components are then loaded onto compromised systems through DLL sideloading techniques. Installers for these components are often retrieved from legitimate hosting services such as Catbox and Wasabi, a tactic that helps malicious network traffic blend in with routine cloud-based activity, making detection more challenging.

In one documented intrusion involving critical infrastructure, malicious activity commenced on July 22, 2026, with the appearance of a webshell on a SharePoint server. The attackers proceeded to execute reconnaissance commands like whoami, net user /domain, and nltest /domain_trusts. They then deployed sideloading pairs and utilized NetExec for Active Directory discovery, credential spraying, and remote execution across the network. Furthermore, the group installed a Microsoft-signed executable, code-insiders.exe, as a service and abused Visual Studio Code’s built-in tunnel functionality. This created a covert access channel through infrastructure that defenders might mistakenly associate with legitimate administrative or developer tools.

Prior to initiating the encryption phase, the Longlegs group rapidly deployed an anti-virus (AV) and endpoint detection and response (EDR) termination utility to at least 40 hosts within approximately two hours. Recent operations have incorporated a “bring-your-own-vulnerable-driver” technique, leveraging the signed but vulnerable K7RKScan driver, identified as CVE-2025-1055. This driver allows them to terminate privileged processes from kernel space. NIST describes this vulnerability as stemming from missing authorization in the driver’s IOCTL handler, affecting K7 Security Anti-Malware versions predating 23.0.0.10. Investigators noted that the specific driver used in this particular intrusion could not be definitively confirmed.

Warlock ransomware encryption followed almost immediately on at least 33 systems. The attackers strategically placed the ransomware executables (run.exe, rune.exe) and the ransom note, “how to restore your files.txt,” within the compromised domain’s SYSVOL share. Because SYSVOL is replicated across all domain controllers and is readable domain-wide, the Distributed File System Replication mechanism inadvertently facilitated the widespread distribution of the ransomware payload, effectively transforming trusted Active Directory infrastructure into a ransomware delivery channel.

This campaign underscores that patching vulnerabilities alone is insufficient after suspected SharePoint exploitation. Defenders must actively hunt for webshells and anomalous SharePoint worker-process behavior. Following the removal of any persistence mechanisms, it is crucial to rotate ASP.NET and IIS machine keys, enable AMSI in Full Mode, and deploy robust EDR solutions. Furthermore, restricting SharePoint’s internet exposure and meticulously inspecting suspicious ToolPane.aspx requests are vital. CISA also advises placing any necessary public-facing SharePoint deployments behind an authenticated Layer 7 proxy and blocking external access to Central Administration. For operators in the water, telecommunications, government, and education sectors, delayed remediation can quickly escalate from a single compromised collaboration server to domain-wide operational disruption. The observed targeting pattern might indicate either the prevalence of vulnerable, exposed servers or a deliberate regional focus. Regardless of the underlying motivation, both scenarios necessitate immediate asset discovery, containment, and comprehensive recovery planning.

File Indicators

SHA-256 Hash Classification
116ca4e88a1bcebb6c0da7fb431c8eca7b8ef3f9767194820c56091972ccac2c Warlock ransomware
155fb1cbdaea12c83ba92d18c88cf38bbc42bb684f913ca0bc26fcf115426a55 Warlock ransomware
1edb2c0b537cd95bbd5fc16321b4c38a6adf325ccc7b588ad6acc980b0463b60 Malicious DLL
206f27ae820783b7755bca89f83a0fe096dbb510018dd65b63fc80bd20c03261 Malicious DLL
27b7591cf9e1283010ca98fa5dbe970a73fee0d8cde277639924c144718db7c0 Malicious DLL
37f94fe1b4a106f02b6f74a69cbc05e69c17406f688beef4c9a045ffcbd2e65e Suspicious file
6d07f1232dc59b84038fd0b2e75fdd3d5b825882bb0dba9e6724b7b0823fa3ad Warlock ransomware
73c5268256c9da5488cd9e2b79013060ac321c7e54129344dc7b51e268af36ea AV/EDR killer
8b58f7811a2a2f2a5024220490473774f02759dd2dd904b5b9fabfbaae37125f Warlock ransomware
8ce8d8270ee9de02644530b8dd7fa78973b4a3b80f121e2c5f45ae68cce196f9 Warlock ransomware
9ceb01f8bf7d6dba2ae07f5bd6070de3ec67b5eb01f969b0ba85e74564fb83a7 Suspicious file
aaff04d84ef85353966aa4af186ff1254b72c068f33f802417b29dc23fb9f192 Suspicious file
ae9f7fce57c7b928e659dccf0e00fa79cd9cd61a106f18d4e03f92dc3a03c295 Vulnerable driver
c46825fcc0d1bf7a8b192facb176d6bf916c9dccfd6fa994be691e3b0e585f4e Malicious DLL
e14240bac8277b0f6dd4d29ab5da20d246bcccae647e5fe8d19cdae7fe471b20 Malicious DLL
e3204b05e2f3a29bb6e6fcc21dda77d7cd31dfa755c21da0aa8661b5619ee0a1 Suspicious file
eea631b5f7125239db0811e4682c2316ead69f9822e02d94fb5d8bf0d2faebed Suspicious file
f7269f80f81e99d06a590d7ab374e12fdf7e5f55a02c2a46c342d670f8519fdf Suspicious file
fb3846c9ac53d1b841ada3a6b1091153fea41a169cb44fe0084097d1f4d45984 Malicious DLL

Network Indicators

Network IoC Type Observed Role
litter[.]catbox[.]moe Defanged hostname Payload-hosting and malware-delivery infrastructure
xn8xyt-drop[.]s3[.]wasabisys[.]com Defanged hostname Cloud-storage endpoint used to retrieve a malicious MSI package

What You Should Do

  • Patch Immediately: Ensure all Microsoft SharePoint Server instances are updated with the latest security patches to address CVE-2025-49704, CVE-2025-49706, CVE-2025-537

    Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

    Tags:

    AttackCVEExploitMalwarePatchransomwareSecurityThreat

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

Critical Axios HTTP/2 Vulnerabilities Allow SSRF and DoS Attacks

Next Post

WordPress Malware Returns With Self-Healing Backdoor

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical Node.js Vulnerability CVE-2024-27983 Allows Remote Code Execution
October 1, 2026
Critical Zimbra RCE Flaw CVE-2022-27925 Actively Exploited
October 1, 2026
Critical ModSecurity Flaws Let Attackers Bypass WAF Protections
October 1, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us