SYMANTEC’S report confirms that Warlock ransomware, linked to Longlegs (Storm-2603) and tied to older China-nexus clusters, continues to exploit a chain of SharePoint flaws known as ToolShell to breach critical infrastructure. In a run of attacks over July 2026, attackers compromised a water utility, a telecom provider, a regional government body and a university, with victims in Portuguese- and Spanish-speaking countries across Europe, Africa and Latin America.
The intrusion begins with a webshell placed in the SharePoint LAYOUTS directory, followed by theft of the server’s ASP[.]NET machine keys to forge a signed payload that executes within SharePoint. The group then uses DLL sideloading and pulls additional payloads from legitimate hosting services (for example catbox[.]moe and wasabisys[.]com) to blend traffic with normal activity.
Once inside, the attackers disable security tools using a vulnerable signed driver named K7RKScan and establish remote access by installing Visual Studio Code’s tunneling feature as a service. Symantec’s investigation traces rapid lateral movement: after disabling protection, Warlock is deployed to multiple hosts via the domain’s SYSVOL share, with dfsrs[.]exe distributing the malicious files across domain controllers.
They also documented the use of a deserialization gadget to turn a forged, signed payload into code execution, followed by the deployment of three installer packages within ninety minutes. By 31 July, a tool designed to disable AV/EDR had been pushed to around 40 hosts before Warlock was installed on at least 33 machines.
The incident underscores that ToolShell remains a viable initial access method where SharePoint patches and mitigations are missing, and cites the need to review on‑premises SharePoint against the July 2026 CISA advisory.