NEWS

Warlock Ransomware Hits Large Spanish, Portuguese Orgs

China-nexus actor Longlegs (Storm-2603) hit a water utility, telecom, government body, and university in Iberia and Latin America via SharePoint flaws.

Dylan H.

News Desk

October 1, 2026
8 min read
Warlock Ransomware Hits Large Spanish, Portuguese Orgs

A Cybercrime Gang That Behaves Like a State-Backed APT

A China-nexus threat actor that researchers have tracked for more than a year under the name Longlegs — also known as Storm-2603 (Microsoft), CL-CRI-1040 (Palo Alto Unit 42), CamoFei (TeamT5), and ChamelGang (SentinelOne) — has pivoted its Warlock ransomware operation toward a new and unusual set of targets: large organizations in Portuguese- and Spanish-speaking countries across Europe, Africa, and Latin America. According to Symantec, in the past two months the group has hit at least four large organizations, including a water utility, a telecommunications operator, a regional government body, and a university. The group's defining trait, as researchers describe it, is that it "looks like a cybercrime gang, acts like a state-associated APT" — it deploys ransomware indiscriminately for apparent financial gain, yet relies on tradecraft (custom command-and-control frameworks, forged cryptographic material, kernel-level evasion) more commonly associated with nation-state espionage operators. More than a year after its debut, analysts remain unable to say with confidence whether Longlegs is a financially motivated crew borrowing APT-grade tooling, or a state-associated group moonlighting in ransomware.


Incident Details

AttributeValue
Threat actorLonglegs (Symantec) — aka Storm-2603 (Microsoft), CL-CRI-1040 (Unit 42), CamoFei (TeamT5), ChamelGang (SentinelOne)
Ransomware familyWarlock (possibly a rebrand of Anylock; some samples append a .x2anylock extension)
OriginChina-nexus; activity traced as far back as 2019 under earlier cluster names
First observed (Warlock)June 2025
Breakout eventExploitation of the ToolShell SharePoint zero-day, July 19, 2025
Recent campaign windowPast two months (reported by Symantec)
Recent victimsWater utility, telecommunications operator, regional government body, university
Victim geographyPortuguese- and Spanish-speaking countries across Europe, Africa, and Latin America
Historical geographyUS, Japan, UK, France, Poland, Turkey, Canada, India, Hong Kong, Bermuda, Brazil, Taiwan, Russia
Primary initial accessSharePoint ASPX webshell planted in the LAYOUTS directory
Key vulnerabilitiesCVE-2025-53770 (ToolShell), CVE-2025-1055 (K7RKScan BYOVD driver)
Confirmed incidents (Storm-2603)At least 11 since mid-July 2025

How It Worked

Initial Access: SharePoint Webshells and Forged Tokens

Longlegs' primary entry point remains on-premises Microsoft SharePoint Server. The group plants an ASPX webshell inside SharePoint's LAYOUTS directory, often targeting several product versions simultaneously to maximize the chance of a working exploit. From there, the webshell extracts the server's ASP.NET machine keys, which the attackers use to forge signed __VIEWSTATE payloads — allowing arbitrary code execution inside the SharePoint application pool without needing valid credentials. The technique traces back to the ToolShell exploit chain (CVE-2025-53770), disclosed as a zero-day on July 19, 2025, though Symantec notes the group continues exploiting SharePoint flaws more than a year later, including newer vulnerabilities added to CISA's Known Exploited Vulnerabilities catalog.

Microsoft has said three distinct China-linked actors were separately exploiting the SharePoint zero-day: Budworm (aka Linen Typhoon, APT27), Sheathminer (aka Violet Typhoon, APT31), and Storm-2603 — the actor behind Warlock, which also deployed LockBit in some intrusions.

Defense Evasion: Mass AV/EDR Termination via BYOVD

Before encryption begins, Longlegs pushes an AV and EDR termination utility across the victim's environment — in one documented case, to at least 40 hosts in roughly two hours. Recent operations abuse the signed but vulnerable K7RKScan driver (CVE-2025-1055) in a classic bring-your-own-vulnerable-driver (BYOVD) technique, terminating security processes from kernel space where user-mode defenses cannot intervene. Earlier campaigns tied to the group's older CatB ransomware used a different vulnerable driver and a stolen code-signing certificate (registered to "coolschool") to lend malicious binaries an air of legitimacy.

Covert Access: Living Off VS Code

For hands-on-keyboard access that blends into legitimate developer traffic, Longlegs has been observed abusing Visual Studio Code's remote tunneling feature — a living-off-the-land technique that lets the operators maintain covert remote access without dropping a dedicated remote-access tool that security products would flag.

Deployment at Scale: SYSVOL Instead of PsExec

Rather than pushing the ransomware binary host-by-host with tools like PsExec or WMI — noisy techniques well understood by defenders — Longlegs stages the Warlock payload in the domain's SYSVOL share. Because SYSVOL is automatically synchronized across all domain controllers via ordinary Active Directory replication, the payload propagates to every domain controller in the environment as a side effect of normal AD housekeeping, with no additional lateral-movement tooling required.

The Pivot to Iberia and Latin America

Warlock's earlier victim set read like "a random sampling" of the world's largest developed economies — the United States, Japan, the United Kingdom, France, Poland, Turkey, Canada, India, Hong Kong, and Bermuda, alongside Brazil, Taiwan, and Russia historically tied to the group's older ChamelGang/CamoFei activity. The recent concentration of victims in Portuguese- and Spanish-speaking countries is a departure from that pattern. Symantec analysts say the shift could reflect newly developed language capabilities within the group, or a deliberate search for less-saturated targets as Western organizations harden their SharePoint deployments and patch faster. Notably, researchers see no evidence Longlegs targets the Commonwealth of Independent States (CIS) region — a self-imposed exclusion zone more typically associated with Russian-speaking ransomware crews avoiding their own backyard, not a China-based operator.

Impact Assessment

Impact AreaDescription
Critical infrastructureCompromise of a water utility and a telecom operator raises service-continuity and public-safety concerns
Government operationsA regional government body's breach risks citizen data exposure and disrupted public services
Education sectorUniversity compromise risks research data, intellectual property, and student/staff PII
Attribution ambiguityThe blurred line between espionage-grade tradecraft and profit-driven ransomware complicates incident response and policy response alike
Ransomware landscapeA China-based actor operating outside the traditionally Russia/CIS-centric ransomware ecosystem breaks established geographic assumptions
Trust infrastructureReuse of stolen code-signing certificates and vulnerable signed drivers undermines the trust model underpinning AV/EDR and code-signing controls

Recommendations

For SharePoint Administrators

  • Apply all outstanding SharePoint Server security updates immediately, prioritizing any CVE listed in CISA's KEV catalog
  • Rotate ASP.NET machine keys on all on-premises SharePoint farms, particularly any that have not been rotated since the ToolShell disclosure
  • Audit the LAYOUTS directory and other web-accessible SharePoint paths for unauthorized .aspx files
  • Where feasible, migrate internet-facing SharePoint workloads to a cloud-hosted model with vendor-managed patching

For Security Operations Teams

  • Hunt for the K7RKScan driver (CVE-2025-1055) and other known-vulnerable signed drivers being loaded outside of expected contexts
  • Alert on mass, rapid AV/EDR process termination across dozens of hosts in a short window — a strong indicator of pre-encryption staging
  • Monitor SYSVOL for unexpected file writes and treat unusual SYSVOL growth as a high-priority detection, not just a backup-and-restore concern
  • Flag outbound connections consistent with VS Code remote tunneling from servers that have no legitimate development function
  • Maintain offline, immutable backups of domain controllers and critical servers given the group's AD-replication-based deployment method

For Government, Utility, and Education-Sector Organizations in Iberia and Latin America

  • Treat the documented targeting shift as an active warning; prioritize SharePoint patching and exposure reduction now rather than after a confirmed incident
  • Join or increase engagement with regional information-sharing bodies (ISACs/CSIRTs) given the apparent deliberate regional pivot
  • Segment OT/ICS networks from corporate IT, particularly for water and telecommunications operators

For End Users

  • Report phishing and suspicious login prompts promptly; initial access in this campaign is server-side, but credential harvesting often supports follow-on activity
  • Enable multi-factor authentication everywhere it is available
  • Keep personal and work devices patched, and avoid reusing credentials across services

Key Takeaways

  1. Longlegs/Storm-2603, a China-nexus actor with ties to activity dating back to 2019, operates the Warlock ransomware and has deployed it in at least 11 confirmed incidents since mid-2025.
  2. The group has pivoted toward Portuguese- and Spanish-speaking countries, hitting a water utility, telecom operator, regional government body, and university in the past two months — a sharp break from its earlier, geographically scattered victim list.
  3. Initial access runs through on-premises SharePoint Server, via webshells and forged __VIEWSTATE tokens rooted in the ToolShell exploit chain (CVE-2025-53770) and newer SharePoint CVEs.
  4. The group disables security tooling at scale using a BYOVD technique (CVE-2025-1055, K7RKScan driver) and deploys ransomware domain-wide via SYSVOL replication rather than conventional lateral-movement tools.
  5. Researchers remain unable to classify Longlegs definitively as either a cybercrime gang or a state-associated APT — its tradecraft resembles espionage operations, but its ransomware deployment resembles indiscriminate financial crime.
  6. Organizations — especially critical infrastructure, government, and education entities in Iberia and Latin America — should treat unpatched on-premises SharePoint as an active, currently exploited exposure, not a theoretical risk.

Sources