Warlock Ransomware Exploits Critical SharePoint Flaws in Water, Telecom Attacks
Key Takeaways A China-linked threat actor, known as Longlegs or Storm-2603, is actively exploiting critical vulnerabilities in Microsoft SharePoint Server. The campaign targets essential service...
Key Takeaways
- A China-linked threat actor, known as Longlegs or Storm-2603, is actively exploiting critical vulnerabilities in Microsoft SharePoint Server.
- The campaign targets essential service providers and public sector organizations, including water utilities, telecommunications companies, government bodies, and universities.
- Warlock ransomware is the primary payload, impacting organizations across Europe, Africa, and Latin America.
- The attacks leverage a sophisticated “ToolShell” exploit chain and subsequent bypasses, along with a vulnerable driver (CVE-2025-1055) to disable security software.
- Defenders must implement comprehensive strategies beyond patching, focusing on webshell detection, key rotation, and network segmentation to mitigate risks.
A sophisticated threat actor, believed to be operating from China, continues to leverage critical vulnerabilities within Microsoft SharePoint Server to deploy Warlock ransomware. Recent operations have targeted vital infrastructure and public sector entities in Portuguese- and Spanish-speaking regions.
Table Of Content
Security researchers at Symantec identify this group as Longlegs, while Microsoft tracks them under the designation Storm-2603. The group’s past activities have also been associated with other aliases, including CL-CRI-1040, CamoFei, and ChamelGang.
Over the past two months, this campaign has successfully breached at least four distinct organizations: a water utility, a telecommunications provider, a regional government agency, and an academic institution. These attacks have spanned geographical locations across Europe, Africa, and Latin America, highlighting the global reach and indiscriminate nature of the threat.
Warlock Ransomware Exploiting SharePoint Flaws
Warlock ransomware first emerged in June 2025, quickly gaining notoriety for its deployment via the “ToolShell” exploit chain in SharePoint. This initial chain leveraged a combination of vulnerabilities, specifically CVE-2025-49704 and CVE-2025-49706. Subsequent bypasses to these exploits were later identified and assigned CVE-2025-53770 and CVE-2025-53771.
The Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that this exploit chain facilitates unauthorized access to on-premises SharePoint servers, leading to the exposure of internal configurations and enabling remote code execution. Warlock ransomware was frequently observed as the final payload on systems compromised through these vulnerabilities. Even with the disclosure of newer SharePoint flaws in 2026, the attack surface remains significant, with CISA issuing warnings about active exploitation affecting supported on-premises editions.
According to research published by Symantec, the Longlegs group typically establishes persistence by planting an ASPX webshell within SharePoint’s LAYOUTS directory. This tactic often targets multiple SharePoint product versions concurrently.
Once deployed, the webshell is designed to extract ASP.NET machine keys. This critical step enables the attackers to forge signed __VIEWSTATE payloads, allowing them to execute arbitrary code directly within the SharePoint application pool. Subsequent malware components are then loaded onto compromised systems through DLL sideloading techniques. Installers for these components are often retrieved from legitimate hosting services such as Catbox and Wasabi, a tactic that helps malicious network traffic blend in with routine cloud-based activity, making detection more challenging.
In one documented intrusion involving critical infrastructure, malicious activity commenced on July 22, 2026, with the appearance of a webshell on a SharePoint server. The attackers proceeded to execute reconnaissance commands like whoami, net user /domain, and nltest /domain_trusts. They then deployed sideloading pairs and utilized NetExec for Active Directory discovery, credential spraying, and remote execution across the network. Furthermore, the group installed a Microsoft-signed executable, code-insiders.exe, as a service and abused Visual Studio Code’s built-in tunnel functionality. This created a covert access channel through infrastructure that defenders might mistakenly associate with legitimate administrative or developer tools.
Prior to initiating the encryption phase, the Longlegs group rapidly deployed an anti-virus (AV) and endpoint detection and response (EDR) termination utility to at least 40 hosts within approximately two hours. Recent operations have incorporated a “bring-your-own-vulnerable-driver” technique, leveraging the signed but vulnerable K7RKScan driver, identified as CVE-2025-1055. This driver allows them to terminate privileged processes from kernel space. NIST describes this vulnerability as stemming from missing authorization in the driver’s IOCTL handler, affecting K7 Security Anti-Malware versions predating 23.0.0.10. Investigators noted that the specific driver used in this particular intrusion could not be definitively confirmed.
Warlock ransomware encryption followed almost immediately on at least 33 systems. The attackers strategically placed the ransomware executables (run.exe, rune.exe) and the ransom note, “how to restore your files.txt,” within the compromised domain’s SYSVOL share. Because SYSVOL is replicated across all domain controllers and is readable domain-wide, the Distributed File System Replication mechanism inadvertently facilitated the widespread distribution of the ransomware payload, effectively transforming trusted Active Directory infrastructure into a ransomware delivery channel.
This campaign underscores that patching vulnerabilities alone is insufficient after suspected SharePoint exploitation. Defenders must actively hunt for webshells and anomalous SharePoint worker-process behavior. Following the removal of any persistence mechanisms, it is crucial to rotate ASP.NET and IIS machine keys, enable AMSI in Full Mode, and deploy robust EDR solutions. Furthermore, restricting SharePoint’s internet exposure and meticulously inspecting suspicious ToolPane.aspx requests are vital. CISA also advises placing any necessary public-facing SharePoint deployments behind an authenticated Layer 7 proxy and blocking external access to Central Administration. For operators in the water, telecommunications, government, and education sectors, delayed remediation can quickly escalate from a single compromised collaboration server to domain-wide operational disruption. The observed targeting pattern might indicate either the prevalence of vulnerable, exposed servers or a deliberate regional focus. Regardless of the underlying motivation, both scenarios necessitate immediate asset discovery, containment, and comprehensive recovery planning.
File Indicators
| SHA-256 Hash | Classification |
|---|---|
116ca4e88a1bcebb6c0da7fb431c8eca7b8ef3f9767194820c56091972ccac2c |
Warlock ransomware |
155fb1cbdaea12c83ba92d18c88cf38bbc42bb684f913ca0bc26fcf115426a55 |
Warlock ransomware |
1edb2c0b537cd95bbd5fc16321b4c38a6adf325ccc7b588ad6acc980b0463b60 |
Malicious DLL |
206f27ae820783b7755bca89f83a0fe096dbb510018dd65b63fc80bd20c03261 |
Malicious DLL |
27b7591cf9e1283010ca98fa5dbe970a73fee0d8cde277639924c144718db7c0 |
Malicious DLL |
37f94fe1b4a106f02b6f74a69cbc05e69c17406f688beef4c9a045ffcbd2e65e |
Suspicious file |
6d07f1232dc59b84038fd0b2e75fdd3d5b825882bb0dba9e6724b7b0823fa3ad |
Warlock ransomware |
73c5268256c9da5488cd9e2b79013060ac321c7e54129344dc7b51e268af36ea |
AV/EDR killer |
8b58f7811a2a2f2a5024220490473774f02759dd2dd904b5b9fabfbaae37125f |
Warlock ransomware |
8ce8d8270ee9de02644530b8dd7fa78973b4a3b80f121e2c5f45ae68cce196f9 |
Warlock ransomware |
9ceb01f8bf7d6dba2ae07f5bd6070de3ec67b5eb01f969b0ba85e74564fb83a7 |
Suspicious file |
aaff04d84ef85353966aa4af186ff1254b72c068f33f802417b29dc23fb9f192 |
Suspicious file |
ae9f7fce57c7b928e659dccf0e00fa79cd9cd61a106f18d4e03f92dc3a03c295 |
Vulnerable driver |
c46825fcc0d1bf7a8b192facb176d6bf916c9dccfd6fa994be691e3b0e585f4e |
Malicious DLL |
e14240bac8277b0f6dd4d29ab5da20d246bcccae647e5fe8d19cdae7fe471b20 |
Malicious DLL |
e3204b05e2f3a29bb6e6fcc21dda77d7cd31dfa755c21da0aa8661b5619ee0a1 |
Suspicious file |
eea631b5f7125239db0811e4682c2316ead69f9822e02d94fb5d8bf0d2faebed |
Suspicious file |
f7269f80f81e99d06a590d7ab374e12fdf7e5f55a02c2a46c342d670f8519fdf |
Suspicious file |
fb3846c9ac53d1b841ada3a6b1091153fea41a169cb44fe0084097d1f4d45984 |
Malicious DLL |
Network Indicators
| Network IoC | Type | Observed Role |
|---|---|---|
litter[.]catbox[.]moe |
Defanged hostname | Payload-hosting and malware-delivery infrastructure |
xn8xyt-drop[.]s3[.]wasabisys[.]com |
Defanged hostname | Cloud-storage endpoint used to retrieve a malicious MSI package |
What You Should Do
- Patch Immediately: Ensure all Microsoft SharePoint Server instances are updated with the latest security patches to address CVE-2025-49704, CVE-2025-49706, CVE-2025-537
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.