A China-nexus threat group tracked as Longlegs (Symantec) and Storm-2603 is linked to ongoing exploitation of on-premises SharePoint to deploy the Warlock ransomware. The operators gain initial access by compromising SharePoint servers through ToolShell-style flaws and newer SharePoint bugs warned by CISA in July 2026. After insertion of a web shell into multiple SharePoint version folders, they steal ASP[.]NET machine keys and forge signed requests to execute code on the server.
Symantec notes the attackers subsequently dropped payloads from public file-hosting and cloud storage services to diversify delivery, rather than relying on a single conduit.
In one documented intrusion targeting a critical infrastructure operator, the attack began on 22 July with a web shell on a SharePoint server. Over the following days they conducted reconnaissance, expanded access, and mapped credentials with tools like NetExec. They also used Visual Studio Code’s tunnel feature for remote access and leveraged local admin group privileges on multiple hosts.
By 31 July they deployed a security-killing tool to at least 40 hosts within about two hours, and then the ransomware moved via the domain’s SYSVOL share to approximately 33 hosts. The campaign has previously leveraged a signed but vulnerable driver tracked as CVE-2025-1055 (K7RKScan) to disable security tooling at the kernel level.
Victims include at least four organisations across Portuguese- and Spanish-speaking regions, including a water utility and a telecom provider, plus a regional government body and a university. No ransom amounts or data leaks are reported publicly.
Defences recommended include patching SharePoint for ToolShell and related flaws (per CISA July 2026 advisory), rotating ASP[.]NET machine keys post-patching, blocking vulnerable drivers with Microsoft’s blocklist, monitoring SYSVOL scripts folders, and watching for VS Code tunnels or new local admin accounts. Offline backups remain essential.