NEWS

Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware

China-nexus group Longlegs is still abusing SharePoint ToolShell flaws and a BYOVD EDR killer to deploy Warlock ransomware on critical infrastructure.

Dylan H.

News Desk

October 3, 2026
7 min read
Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware

Warlock Ransomware Keeps Weaponizing Year-Old SharePoint Flaws

A suspected China-linked threat actor behind the Warlock ransomware is still actively exploiting Microsoft SharePoint vulnerabilities — both the year-old "ToolShell" flaws and newer ones — to breach organizations in Portuguese- and Spanish-speaking countries, according to new research from the Symantec and Carbon Black Threat Hunter Team. Warlock, also tracked as Gold Salem, Longlegs, and Storm-2603, first drew attention in June 2025 when it was deployed via zero-day exploitation of SharePoint RCE flaws. Over the past two months, the group has hit at least four organizations — a water utility, a telecommunications provider, a regional government body, and a university — spanning Europe, Africa, and Latin America.

Symantec attributes development of the Warlock payload to a China-nexus cluster it tracks as Longlegs (aka Storm-2603), which it has previously linked to older activity sets known as CL-CRI-1040, CamoFei, and ChamelGang. Researchers noted this is unusual: most ransomware operations are run by groups based in Russia or the CIS, while "Warlock appears to be used by a group based in China."


Campaign Details

AttributeDetail
RansomwareWarlock
Developer/operatorLonglegs (aka Storm-2603), tracked by Symantec
AliasesGold Salem, Longlegs, Storm-2603
AttributionSuspected China-nexus actor
First prominenceJune–July 2025 (ToolShell zero-day exploitation)
Recent victim countAt least 4 organizations in the past two months
Targeted regionsPortuguese- and Spanish-speaking countries — Europe, Africa, Latin America
Sectors hitWater utility, telecommunications, regional government, university
Initial accessExploitation of SharePoint ToolShell CVEs (patched and possibly newer flaws)
EDR/AV evasionBYOVD kernel-level process termination (K7RKScan driver, CVE-2025-1055)
Related clustersCL-CRI-1040, CamoFei, ChamelGang

Initial Access via SharePoint ToolShell

Warlock's initial-access chain traces back to the ToolShell SharePoint exploit chain — CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771 — first exploited as zero-days starting July 18, 2025, and added to CISA's Known Exploited Vulnerabilities catalog two days later. CVE-2025-53770 alone carries a CVSS score of 9.8, enabling unauthenticated remote code execution via unsafe deserialization. More than a year later, Symantec says unpatched or unmitigated on-premises SharePoint deployments remain a viable entry point for Longlegs, whether through those original flaws or newer SharePoint vulnerabilities layered on top.

Once inside a SharePoint farm, the attackers plant an ASPX web shell inside the server's LAYOUTS directory for persistent command execution, then extract the farm's ASP.NET machine keys. Those stolen keys let them forge signed __VIEWSTATE payloads, achieving remote code execution directly inside the SharePoint application pool without needing valid credentials.

Payload Staging via Legitimate Cloud Services

To blend malicious traffic with routine cloud activity, Longlegs retrieves follow-on tooling from legitimate public hosting rather than attacker-owned infrastructure. In one documented intrusion, PowerShell loaded the System.Workflow.ComponentModel assembly — supplying the deserialization gadget needed for the forged payload — and the attackers then used msiexec to pull three separate MSI installer packages from litter.catbox.moe and an S3-compatible Wasabi cloud storage bucket (wasabisys.com) within a 90-minute window. Follow-on malware is loaded via DLL sideloading.

Disabling Security Tools at Scale

The most alarming phase of the kill chain is Longlegs' ability to blind endpoint defenses before detonating ransomware. The attackers deploy a BYOVD (bring-your-own-vulnerable-driver) EDR killer built on the K7RKScan signed driver, tracked as CVE-2025-1055 — the same driver abused separately by the DragonForce ransomware operation. The driver lets the attackers terminate protected security processes at the kernel level, bypassing tamper protection that would normally block an unprivileged process from killing AV/EDR agents.

In one critical-infrastructure intrusion that began on July 22, 2026, the threat actor pushed this security-disabling tool to at least 40 hosts within about two hours, then staged and launched Warlock ransomware on at least 33 hosts.

Lateral Movement and Distribution via SYSVOL

For lateral movement and reconnaissance, Longlegs installs Visual Studio Code Insiders as a Windows service and abuses its built-in remote tunneling feature to maintain interactive access that resembles legitimate developer traffic rather than conventional C2. The group also uses NetExec for Active Directory enumeration and credential spraying.

Rather than pushing the ransomware binary host-by-host with remote execution tools, Longlegs stages the Warlock payload inside the compromised domain's SYSVOL share. Because SYSVOL is automatically replicated to every domain controller via Active Directory's native replication mechanism, the ransomware propagates organization-wide without the attackers needing to touch each endpoint individually — a more efficient and stealthier distribution method than tools like PsExec or WMI.


Impact Assessment

Impact AreaDescription
Critical infrastructure riskWater utility and telecommunications victims raise the stakes beyond data loss to potential service disruption
Detection evasionBYOVD kernel-level AV/EDR termination defeats tamper protection most security products rely on
Scale and speed40 hosts disabled in roughly two hours, 33 hosts ransomed — demonstrates an efficient, well-rehearsed playbook
Infrastructure-light deliveryAbuse of Catbox and Wasabi (S3-compatible) hosting makes payload retrieval hard to distinguish from normal cloud traffic
Novel propagation techniqueSYSVOL/AD-replication staging spreads ransomware without conventional lateral-movement tooling, complicating detection
Ongoing exposureUnpatched or unmitigated on-premises SharePoint, more than a year after ToolShell disclosure, remains an active entry point

Recommendations

For SharePoint Administrators

  • Patch on-premises SharePoint Server against the full ToolShell chain (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, CVE-2025-53771) immediately if not already remediated, and verify no newer SharePoint CVEs remain unpatched
  • Rotate ASP.NET machine keys on any SharePoint farm that was internet-exposed and unpatched during the ToolShell disclosure window, even if no compromise has been confirmed
  • Audit the LAYOUTS directory and other SharePoint web-accessible paths for unauthorized .aspx files
  • Restrict or monitor outbound SharePoint server traffic — a patched, internal application server should rarely need to reach consumer file-hosting or cloud-storage domains

For Security Teams

  • Block or alert on loading of known-vulnerable signed drivers, including K7RKScan (CVE-2025-1055); maintain an up-to-date vulnerable-driver blocklist (Microsoft's recommended block list, WDAC policies)
  • Treat mass, rapid-fire termination of AV/EDR agents across many hosts in a short window as a high-severity indicator of imminent ransomware deployment, not just a tooling glitch
  • Hunt for Visual Studio Code Insiders installed as a Windows service outside of developer workstations, and for unexpected use of its remote-tunnel feature
  • Flag NetExec usage and unusual MSI retrievals from catbox.moe or Wasabi/S3-compatible storage domains
  • Monitor SYSVOL for unauthorized file additions — Active Directory replication of unexpected executables or scripts into SYSVOL is a strong ransomware-staging signal

For Critical Infrastructure and Public Sector Organizations

  • Water utilities, telecom operators, government bodies, and universities in Portuguese- and Spanish-speaking countries across Europe, Africa, and Latin America should treat this as active, regionally focused targeting and prioritize SharePoint patch verification now
  • Segment OT/ICS networks from IT/AD infrastructure so a Warlock-style AD-replication propagation technique cannot reach operational systems
  • Maintain offline, tested backups and an incident response plan that assumes domain controllers may be used as a distribution vector, not just a target

Key Takeaways

  1. Warlock ransomware, developed by the China-nexus cluster Symantec tracks as Longlegs (aka Storm-2603), is still actively exploiting SharePoint ToolShell flaws more than a year after their initial disclosure.
  2. Recent victims include a water utility, a telecommunications provider, a regional government body, and a university across Portuguese- and Spanish-speaking parts of Europe, Africa, and Latin America.
  3. The attackers use a BYOVD EDR killer built on the vulnerable K7RKScan driver (CVE-2025-1055) to disable security software on dozens of hosts within hours before deploying ransomware.
  4. Payload delivery abuses legitimate cloud services — Catbox and Wasabi's S3-compatible storage — to blend malicious downloads with routine traffic.
  5. Warlock's novel distribution technique stages the ransomware in a domain's SYSVOL share, letting Active Directory replication spread it to every domain controller without conventional lateral-movement tools.
  6. Organizations still running unpatched on-premises SharePoint, or that haven't rotated machine keys since the ToolShell disclosure, remain exposed to this ongoing campaign.

Sources