A Cybercrime Gang That Behaves Like a State-Backed APT
A China-nexus threat actor that researchers have tracked for more than a year under the name Longlegs — also known as Storm-2603 (Microsoft), CL-CRI-1040 (Palo Alto Unit 42), CamoFei (TeamT5), and ChamelGang (SentinelOne) — has pivoted its Warlock ransomware operation toward a new and unusual set of targets: large organizations in Portuguese- and Spanish-speaking countries across Europe, Africa, and Latin America. According to Symantec, in the past two months the group has hit at least four large organizations, including a water utility, a telecommunications operator, a regional government body, and a university. The group's defining trait, as researchers describe it, is that it "looks like a cybercrime gang, acts like a state-associated APT" — it deploys ransomware indiscriminately for apparent financial gain, yet relies on tradecraft (custom command-and-control frameworks, forged cryptographic material, kernel-level evasion) more commonly associated with nation-state espionage operators. More than a year after its debut, analysts remain unable to say with confidence whether Longlegs is a financially motivated crew borrowing APT-grade tooling, or a state-associated group moonlighting in ransomware.
Incident Details
| Attribute | Value |
|---|---|
| Threat actor | Longlegs (Symantec) — aka Storm-2603 (Microsoft), CL-CRI-1040 (Unit 42), CamoFei (TeamT5), ChamelGang (SentinelOne) |
| Ransomware family | Warlock (possibly a rebrand of Anylock; some samples append a .x2anylock extension) |
| Origin | China-nexus; activity traced as far back as 2019 under earlier cluster names |
| First observed (Warlock) | June 2025 |
| Breakout event | Exploitation of the ToolShell SharePoint zero-day, July 19, 2025 |
| Recent campaign window | Past two months (reported by Symantec) |
| Recent victims | Water utility, telecommunications operator, regional government body, university |
| Victim geography | Portuguese- and Spanish-speaking countries across Europe, Africa, and Latin America |
| Historical geography | US, Japan, UK, France, Poland, Turkey, Canada, India, Hong Kong, Bermuda, Brazil, Taiwan, Russia |
| Primary initial access | SharePoint ASPX webshell planted in the LAYOUTS directory |
| Key vulnerabilities | CVE-2025-53770 (ToolShell), CVE-2025-1055 (K7RKScan BYOVD driver) |
| Confirmed incidents (Storm-2603) | At least 11 since mid-July 2025 |
How It Worked
Initial Access: SharePoint Webshells and Forged Tokens
Longlegs' primary entry point remains on-premises Microsoft SharePoint Server. The group plants an ASPX webshell inside SharePoint's LAYOUTS directory, often targeting several product versions simultaneously to maximize the chance of a working exploit. From there, the webshell extracts the server's ASP.NET machine keys, which the attackers use to forge signed __VIEWSTATE payloads — allowing arbitrary code execution inside the SharePoint application pool without needing valid credentials. The technique traces back to the ToolShell exploit chain (CVE-2025-53770), disclosed as a zero-day on July 19, 2025, though Symantec notes the group continues exploiting SharePoint flaws more than a year later, including newer vulnerabilities added to CISA's Known Exploited Vulnerabilities catalog.
Microsoft has said three distinct China-linked actors were separately exploiting the SharePoint zero-day: Budworm (aka Linen Typhoon, APT27), Sheathminer (aka Violet Typhoon, APT31), and Storm-2603 — the actor behind Warlock, which also deployed LockBit in some intrusions.
Defense Evasion: Mass AV/EDR Termination via BYOVD
Before encryption begins, Longlegs pushes an AV and EDR termination utility across the victim's environment — in one documented case, to at least 40 hosts in roughly two hours. Recent operations abuse the signed but vulnerable K7RKScan driver (CVE-2025-1055) in a classic bring-your-own-vulnerable-driver (BYOVD) technique, terminating security processes from kernel space where user-mode defenses cannot intervene. Earlier campaigns tied to the group's older CatB ransomware used a different vulnerable driver and a stolen code-signing certificate (registered to "coolschool") to lend malicious binaries an air of legitimacy.
Covert Access: Living Off VS Code
For hands-on-keyboard access that blends into legitimate developer traffic, Longlegs has been observed abusing Visual Studio Code's remote tunneling feature — a living-off-the-land technique that lets the operators maintain covert remote access without dropping a dedicated remote-access tool that security products would flag.
Deployment at Scale: SYSVOL Instead of PsExec
Rather than pushing the ransomware binary host-by-host with tools like PsExec or WMI — noisy techniques well understood by defenders — Longlegs stages the Warlock payload in the domain's SYSVOL share. Because SYSVOL is automatically synchronized across all domain controllers via ordinary Active Directory replication, the payload propagates to every domain controller in the environment as a side effect of normal AD housekeeping, with no additional lateral-movement tooling required.
The Pivot to Iberia and Latin America
Warlock's earlier victim set read like "a random sampling" of the world's largest developed economies — the United States, Japan, the United Kingdom, France, Poland, Turkey, Canada, India, Hong Kong, and Bermuda, alongside Brazil, Taiwan, and Russia historically tied to the group's older ChamelGang/CamoFei activity. The recent concentration of victims in Portuguese- and Spanish-speaking countries is a departure from that pattern. Symantec analysts say the shift could reflect newly developed language capabilities within the group, or a deliberate search for less-saturated targets as Western organizations harden their SharePoint deployments and patch faster. Notably, researchers see no evidence Longlegs targets the Commonwealth of Independent States (CIS) region — a self-imposed exclusion zone more typically associated with Russian-speaking ransomware crews avoiding their own backyard, not a China-based operator.
Impact Assessment
| Impact Area | Description |
|---|---|
| Critical infrastructure | Compromise of a water utility and a telecom operator raises service-continuity and public-safety concerns |
| Government operations | A regional government body's breach risks citizen data exposure and disrupted public services |
| Education sector | University compromise risks research data, intellectual property, and student/staff PII |
| Attribution ambiguity | The blurred line between espionage-grade tradecraft and profit-driven ransomware complicates incident response and policy response alike |
| Ransomware landscape | A China-based actor operating outside the traditionally Russia/CIS-centric ransomware ecosystem breaks established geographic assumptions |
| Trust infrastructure | Reuse of stolen code-signing certificates and vulnerable signed drivers undermines the trust model underpinning AV/EDR and code-signing controls |
Recommendations
For SharePoint Administrators
- Apply all outstanding SharePoint Server security updates immediately, prioritizing any CVE listed in CISA's KEV catalog
- Rotate ASP.NET machine keys on all on-premises SharePoint farms, particularly any that have not been rotated since the ToolShell disclosure
- Audit the
LAYOUTSdirectory and other web-accessible SharePoint paths for unauthorized.aspxfiles - Where feasible, migrate internet-facing SharePoint workloads to a cloud-hosted model with vendor-managed patching
For Security Operations Teams
- Hunt for the K7RKScan driver (CVE-2025-1055) and other known-vulnerable signed drivers being loaded outside of expected contexts
- Alert on mass, rapid AV/EDR process termination across dozens of hosts in a short window — a strong indicator of pre-encryption staging
- Monitor SYSVOL for unexpected file writes and treat unusual SYSVOL growth as a high-priority detection, not just a backup-and-restore concern
- Flag outbound connections consistent with VS Code remote tunneling from servers that have no legitimate development function
- Maintain offline, immutable backups of domain controllers and critical servers given the group's AD-replication-based deployment method
For Government, Utility, and Education-Sector Organizations in Iberia and Latin America
- Treat the documented targeting shift as an active warning; prioritize SharePoint patching and exposure reduction now rather than after a confirmed incident
- Join or increase engagement with regional information-sharing bodies (ISACs/CSIRTs) given the apparent deliberate regional pivot
- Segment OT/ICS networks from corporate IT, particularly for water and telecommunications operators
For End Users
- Report phishing and suspicious login prompts promptly; initial access in this campaign is server-side, but credential harvesting often supports follow-on activity
- Enable multi-factor authentication everywhere it is available
- Keep personal and work devices patched, and avoid reusing credentials across services
Key Takeaways
- Longlegs/Storm-2603, a China-nexus actor with ties to activity dating back to 2019, operates the Warlock ransomware and has deployed it in at least 11 confirmed incidents since mid-2025.
- The group has pivoted toward Portuguese- and Spanish-speaking countries, hitting a water utility, telecom operator, regional government body, and university in the past two months — a sharp break from its earlier, geographically scattered victim list.
- Initial access runs through on-premises SharePoint Server, via webshells and forged
__VIEWSTATEtokens rooted in the ToolShell exploit chain (CVE-2025-53770) and newer SharePoint CVEs. - The group disables security tooling at scale using a BYOVD technique (CVE-2025-1055, K7RKScan driver) and deploys ransomware domain-wide via SYSVOL replication rather than conventional lateral-movement tools.
- Researchers remain unable to classify Longlegs definitively as either a cybercrime gang or a state-associated APT — its tradecraft resembles espionage operations, but its ransomware deployment resembles indiscriminate financial crime.
- Organizations — especially critical infrastructure, government, and education entities in Iberia and Latin America — should treat unpatched on-premises SharePoint as an active, currently exploited exposure, not a theoretical risk.