The Warlock ransomware group, tracked by Symantec as Longlegs and also known as Storm-2603, continues to exploit unpatched vulnerabilities in Microsoft SharePoint, more than a year after these flaws were initially publicized. The group, which has historical ties to China-nexus clusters CL-CRI-1040, CamoFei, and ChamelGang, has recently targeted critical infrastructure, including water utilities and telecommunications providers, alongside government entities and universities across multiple continents.
The vulnerabilities, collectively referred to as ToolShell, first gained attention in mid-2025. Despite their age, they remain an effective entry point for the attackers. Longlegs typically establishes initial access by placing a webshell in the SharePoint LAYOUTS directory, designed to function across various SharePoint versions. Following this, the attackers steal the server's ASP.NET machine keys to craft a signed payload, enabling arbitrary code execution within the SharePoint application. This method relies on the presence of unpatched SharePoint servers.
In the past two months alone, Longlegs has compromised at least four organizations: a water utility, a telecom provider, a regional government body, and a university. These recent targets are located in Portuguese or Spanish-speaking countries across Europe, Africa, and Latin America. However, the group's targeting is not geographically restricted, with previous attacks observed in the US, Brazil, India, Russia, Taiwan, and Japan. The recent focus on specific language regions may indicate either a search for any exposed and unpatched SharePoint servers or a deliberate targeting strategy.
Once inside a network, the attackers employ DLL sideloading to execute additional payloads. These files are often downloaded from legitimate hosting services such as catbox.moe and wasabisys.com, which helps obscure the malicious traffic. Before deploying the ransomware, Longlegs utilizes a signed but vulnerable driver, K7RKScan, to disable security software, a technique known as "bring your own vulnerable driver." The group has also been observed installing Visual Studio Code's tunneling feature as a service, providing covert remote access that can mimic normal developer activity.
Symantec detailed a specific attack against a critical infrastructure operator that commenced on July 22, 2026, with the deployment of a webshell on a SharePoint server. Within two days, the attackers performed reconnaissance, removed staging files, and introduced DLL sideloading tools. By July 28, they initiated exploitation using a deserialization gadget to achieve code execution within SharePoint via a forged, signed payload. The attackers then retrieved three distinct installer packages from two different hosting services within 90 minutes, suggesting preparedness with multiple delivery options.
The intrusion rapidly expanded from the initial two SharePoint servers to the broader domain. On July 28 and 29, the attackers repeatedly added a domain account named SPSEPRDSetup to the local Administrators group on three additional hosts, leveraging a name that could blend in with legitimate SharePoint-related accounts. By July 31, a tool designed to disable antivirus and EDR solutions was deployed across the network. In one instance, this tool was pushed to at least 40 hosts within approximately two hours.
Immediately following the disabling of security software, Warlock ransomware was deployed. The attackers utilized the domain's SYSVOL share to distribute the ransomware, taking advantage of its automatic replication across domain controllers. Symantec observed the malicious files being delivered via normal domain replication traffic, specifically through the dfsrs.exe Windows service. The rapid progression from disabling protection to encrypting systems highlights the speed and efficiency of the attacks.
The continued success of Warlock ransomware underscores the ongoing risk posed by unpatched SharePoint vulnerabilities. Organizations running on-premises SharePoint installations are strongly advised to ensure all relevant patches and mitigations are applied to prevent exploitation by groups like Longlegs.






