Warlock Ransomware Expands SharePoint Campaign Against Critical Infrastructure
A China-nexus threat actor tracked by Symantec as Longlegs (also known as Storm-2603, Gold Salem, and linked to earlier clusters CL-CRI-1040, CamoFei, and ChamelGang) has been deploying Warlock ransomware against critical infrastructure operators in Portuguese- and Spanish-speaking countries, according to a new report from the Symantec Threat Hunter Team published in October 2026. Over the past two months, the group has compromised at least four victim organizations spanning Europe, Africa, and Latin America, including a water utility, a telecommunications provider, a regional government body, and a university. The attacks exploit unpatched Microsoft SharePoint vulnerabilities, including the 2025 "ToolShell" flaws and newer SharePoint issues flagged by CISA in July 2026.
Incident Details
| Attribute | Value |
|---|---|
| Ransomware | Warlock |
| Threat Actor | Longlegs (aka Storm-2603, Gold Salem) |
| Prior Clusters | CL-CRI-1040, CamoFei, ChamelGang |
| Prior Toolset | LockBit (before pivoting to Warlock) |
| Attack Vector | Microsoft SharePoint exploitation |
| Key CVEs (ToolShell, 2025) | CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, CVE-2025-53771 |
| Defense Evasion CVE | CVE-2025-1055 (K7RKScan vulnerable driver, BYOVD) |
| Victim Count (recent wave) | At least 4 organizations, past 2 months |
| Sectors Hit | Water utility, telecommunications, regional government, higher education |
| Regions | Portuguese- and Spanish-speaking countries across Europe, Africa, Latin America |
| Reporting Source | Symantec Threat Hunter Team |
| Scale in One Intrusion | Security software disabled on ~40 hosts; ransomware deployed on 33 hosts |
How the Attacks Work
Initial Access via SharePoint Exploitation
Warlock emerged in June 2025 and drew widespread attention weeks later when operators were caught exploiting zero-day vulnerabilities in on-premises Microsoft SharePoint Server, collectively dubbed "ToolShell" (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771). Symantec assesses that these flaws remain in the group's active toolkit alongside additional SharePoint vulnerabilities that CISA warned about in a July 2026 advisory covering six newly exploitable issues. Organizations running SharePoint versions at or below the patched baseline (version ≤ the last unpatched cumulative update) remain exposed wherever mitigations have not been applied.
Attackers drop a web shell into the SharePoint LAYOUTS directory across multiple SharePoint versions, which is used to harvest ASP.NET machine keys. Those stolen keys let the group forge authentication payloads and achieve remote code execution on the server without needing valid credentials.
Living-Off-the-Land Reconnaissance and Lateral Movement
Once inside, the operators perform extensive reconnaissance, blending their activity into normal network traffic using a mix of legitimate and dual-use tools, including:
- Visual Studio Code's tunnel feature (
code-insiders.exeinstalled as a persistent service) for covert remote access - NetExec (
nxc.exe) for Active Directory enumeration and credential spraying - DLL sideloading via signed executables such as
ssvagent.exe,logger.exe, anddoexe.exe - msiexec for staged payload delivery
Defense Evasion via BYOVD
To clear a path for encryption, the group abuses K7RKScan, a signed but vulnerable driver tracked as CVE-2025-1055, in a classic Bring Your Own Vulnerable Driver (BYOVD) technique that terminates protected security processes at the kernel level. In one documented intrusion, this tool disabled endpoint security software on roughly 40 hosts within about two hours, clearing the way for Warlock to execute on at least 33 of them.
Domain-Wide Deployment via SYSVOL Staging
Rather than pushing the ransomware binary host-by-host, Warlock operators stage the payload inside the compromised Active Directory domain's SYSVOL share. Because SYSVOL is automatically replicated to every domain controller via Distributed File System Replication (dfsrs.exe) and is readable domain-wide, this technique lets the group trigger near-simultaneous encryption across large swaths of a victim's environment with minimal additional effort.
Regional Targeting Pattern
Symantec researchers noted that the recent focus on Portuguese- and Spanish-speaking countries "suggests either an opportunistic targeting pattern driven by exposed, vulnerable SharePoint servers, or a more deliberate tasking." The firm added that the presence of critical infrastructure operators among the victims "is a reminder of the potential real-world consequences of ransomware attacks that succeed against essential services." This isn't an isolated pattern — by October 2025, separate Warlock/ToolShell incidents had already hit a Middle Eastern telecom provider, government agencies in Africa and South America, and a U.S. university, underscoring the group's broad geographic reach dating back over a year.
Impact Assessment
| Impact Area | Description |
|---|---|
| Operational Disruption | Encryption of systems at a water utility and telecom provider raises risk of service disruption to essential infrastructure |
| Data Exposure | Pre-encryption reconnaissance and credential harvesting suggest likely data theft ahead of encryption, consistent with double-extortion ransomware operations |
| Domain-Wide Blast Radius | SYSVOL staging allows rapid, near-simultaneous encryption across many hosts once domain access is achieved |
| Detection Evasion | BYOVD kernel-level AV/EDR termination and living-off-the-land tooling reduce the chance of early detection |
| Regional Risk Concentration | Portuguese- and Spanish-speaking critical infrastructure operators in Europe, Africa, and Latin America face elevated exposure |
| Recurrence Risk | Longlegs has sustained SharePoint/ToolShell exploitation for over a year, indicating the technique remains a reliable initial access route |
Recommendations
For SharePoint Administrators
- Patch immediately against the ToolShell vulnerabilities (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, CVE-2025-53771) and the additional SharePoint flaws detailed in CISA's July 2026 advisory.
- Rotate ASP.NET machine keys on any SharePoint Server that was internet-exposed and unpatched during the exploitation window, since stolen keys can be reused even after patching.
- Audit the
LAYOUTSdirectory and other SharePoint web-accessible paths for unauthorized.aspxfiles or web shells. - Restrict direct internet exposure of on-premises SharePoint Server deployments where feasible, placing them behind a reverse proxy or VPN with strict access controls.
For Security Teams
- Hunt for K7RKScan and other vulnerable signed drivers on endpoints; block known-vulnerable driver hashes via Microsoft's vulnerable driver blocklist or application control policies.
- Monitor SYSVOL for unexpected file writes, particularly executables or scripts staged outside normal Group Policy content, and alert on unusual
dfsrs.exereplication activity. - Flag anomalous use of living-off-the-land tools such as
net,whoami, andnltest, and monitor for unauthorized installation of VS Code tunnel services orcode-insiders.exerunning as a persistent service. - Watch for NetExec (
nxc.exe) activity and unusual Active Directory enumeration or credential-spraying patterns. - Segment OT/critical infrastructure networks from general IT environments to limit the blast radius of a domain-wide ransomware deployment.
For Critical Infrastructure Operators
- Maintain offline, tested backups of operational and administrative systems, and rehearse recovery procedures specifically for domain-wide encryption scenarios.
- Engage incident response support in advance and establish relationships with national CERTs, given the real-world consequences of ransomware against essential services.
- Treat SharePoint as a Tier-1 asset in vulnerability management programs, given its proven history as an initial access vector for ransomware operators.
Key Takeaways
- Warlock ransomware, operated by the China-nexus actor Longlegs (Storm-2603/Gold Salem), has compromised at least four critical infrastructure and public-sector organizations in Portuguese- and Spanish-speaking countries over the past two months.
- The group's primary initial access vector remains unpatched Microsoft SharePoint, exploiting both the 2025 ToolShell flaws and newer vulnerabilities flagged by CISA in July 2026.
- A BYOVD technique using the vulnerable K7RKScan driver (CVE-2025-1055) let attackers disable security software on roughly 40 hosts in under two hours before deploying ransomware on 33 of them.
- SYSVOL staging enables domain-wide, near-simultaneous ransomware deployment, dramatically increasing the blast radius once domain-level access is achieved.
- Targeted sectors include water utilities, telecommunications, regional government, and higher education — a reminder that ransomware against essential services carries real-world operational risk beyond data loss.
- This activity has persisted for over a year, showing that unpatched SharePoint servers remain a durable and repeatable initial access route for this threat actor.