
Warlock ransomware made headlines back in mid-2025 for exploiting a chain of SharePoint zero-days collectively dubbed ToolShell. More than a year later, the same group is still using that door, and it’s still getting in.
Symantec tracks the group behind Warlock as Longlegs, also known as Storm-2603, and ties it back to older China-nexus clusters called CL-CRI-1040, CamoFei, and ChamelGang. In the past two months alone, Longlegs hit at least four organizations: a water utility, a telecom provider, a regional government body, and a university. All four sit in Portuguese or Spanish speaking countries, spread across Europe, Africa, and Latin America.
Warlock has already targeted organizations in the US, Brazil, India, Russia, Taiwan, and Japan, so the group is not focused on one specific region. The recent attacks on Portuguese- and Spanish-speaking countries could simply mean the attackers are looking for exposed and unpatched SharePoint servers wherever they can find them. They could also be working from a specific target list. Either way, targeting a water utility and a telecom company within a few weeks is something defenders should take seriously.
SharePoint is still the main entry point. Longlegs places a webshell in the LAYOUTS directory and designs it to work across different SharePoint versions. The attackers then steal the server’s ASP.NET machine keys and use them to create a signed payload that can execute code inside the SharePoint application. The technique is effective, but it depends on finding SharePoint servers that have not been properly patched.
Once they get inside, the attackers use DLL sideloading to run additional payloads. They download these files from legitimate hosting services such as catbox.moe and wasabisys.com, which helps the traffic blend in with normal activity.
Before deploying the ransomware, Longlegs also uses a signed but vulnerable driver called K7RKScan to disable security software. This is a common “bring your own vulnerable driver” technique. The attackers have also installed Visual Studio Code’s tunneling feature as a service, giving them remote access that can look like normal developer activity.
“The group continues to favor SharePoint-related vulnerabilities to gain initial access to targeted organizations.” states the report. “Longlegs abuses a vulnerable, signed driver (K7RKScan) to disable security software before deploying ransomware, and has also been observed abusing Visual Studio Code’s tunneling feature for covert remote access.”
Symantec’s report traces a full attack against a critical infrastructure operator starting July 22, 2026, when the webshell first landed on a SharePoint server. Two days later the attackers ran basic recon commands, deleted some staging files, and dropped a pair of DLL sideloading tools. A few days after that, they pinged a Burp Collaborator subdomain baked with the target’s own domain name, which is a scanner’s way of confirming its injected code actually ran.
By July 28 the real exploitation began, using a deserialization gadget to turn a forged, signed payload into code execution inside SharePoint. The attackers then pulled three separate installer packages from two different hosting services within ninety minutes, suggesting they had backups ready in case one path got blocked.
“Two different public hosting services and three distinct package names within the space of ninety minutes suggests the attackers had more than one payload ready to go and were not relying on a single point of delivery.” continues the report. “The intrusion then broadened from the two initial SharePoint servers to the wider domain. Later that day and into the next (July 29) the attackers repeatedly added a domain account named SPSEPRDSetup to the local Administrators group on three further hosts (Computer 3, Computer 4, and Computer 5):”
They spread out to more hosts by adding a fake-sounding admin account named SPSEPRDSetup, a decent bit of social camouflage since SharePoint really does create accounts with that kind of prefix.
On July 31, the attackers deployed a tool designed to disable antivirus and EDR across the network in a short period.
“In one intrusion against a critical infrastructure operator, the attackers pushed a tool designed to disable security software to at least 40 hosts within about two hours, then deployed Warlock on at least 33 hosts by staging it in the domain’s SYSVOL share, where ordinary domain replication delivered it to machines.” Symantec states.
Warlock ransomware was then deployed almost immediately after the security tools were disabled. This was not a slow attack. The attackers moved quickly from disabling protection to encrypting systems.
The attackers also used the domain’s SYSVOL share to distribute the ransomware. SYSVOL is automatically replicated across domain controllers, making it an effective way to spread files across a Windows domain. Symantec found that the ransomware was delivered through normal domain replication traffic, with three systems capturing dfsrs.exe, the Windows service responsible for that replication, delivering the malicious files.
The lesson here isn’t subtle. ToolShell and its related SharePoint flaws are still a working way into a network more than a year after they first made news, and that only holds true because some organizations haven’t patched or mitigated them yet. If you’re running on-premises SharePoint Server and haven’t checked it against CISA’s July 2026 advisory, that’s worth doing before your Monday coffee gets cold.
“Longlegs’ continued activity, more than a year after Warlock ransomware first came to prominence, shows that exploitation of ToolShell and other related-SharePoint vulnerabilities remains a viable initial access route for attackers SharePoint deployments that have not been patched or otherwise mitigated.” concludes the report. “The apparent recent focus on Portuguese- and Spanish-speaking countries suggests either an opportunistic targeting pattern driven by exposed, vulnerable SharePoint servers, or a more deliberate tasking. The inclusion of critical infrastructure operators among the victims is a reminder of the potential real-world consequences of ransomware attacks that succeed against essential services.”
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, Warlock ransomware)