Warlock Ransomware Exploiting SharePoint Flaws to Attack Water and Telecom Operators
China-nexus Longlegs deploys Warlock ransomware via exploited SharePoint flaws against water utility, telecom, government, and university targets across three continents.
Symantec reports that China-nexus actor Longlegs (Microsoft: Storm-2603; also linked to ChamelGang/CamoFei) is exploiting Microsoft SharePoint Server vulnerabilities to deploy Warlock ransomware, compromising at least four organizations in two months, including a water utility, telecom provider, regional government, and university across Europe, Africa, and Latin America. Initial access leverages the ToolShell chain (CVE-2025-49704, CVE-2025-49706) and bypasses (CVE-2025-53770, CVE-2025-53771), with an ASPX webshell in the LAYOUTS directory extracting ASP.NET machine keys to forge signed __VIEWSTATE RCE payloads. Attackers used NetExec for AD discovery and credential spraying, an AV/EDR killer pushed to roughly 40 hosts in two hours, and the vulnerable K7RKScan driver (CVE-2025-1055) as BYOVD. Warlock encrypted at least 33 systems, distributed via the domain's SYSVOL share through DFS replication.
- Longlegs/Storm-2603 hit a water utility, telecom, government body, and university across three continents.
- Initial access via SharePoint ToolShell chain (CVE-2025-49704/49706) and bypasses (CVE-2025-53770/53771).
- Webshell extracts ASP.NET machine keys to forge signed __VIEWSTATE remote-code-execution payloads.
- AV/EDR killer hit ~40 hosts in two hours; Warlock encrypted 33 systems via SYSVOL DFSR replication.
- Vulnerable signed K7RKScan driver (CVE-2025-1055) used to kill privileged processes from kernel space.
Vulnerabilities mentionedAll →
- CVE-2025-10555.6<1%A vulnerability in the K7RKScan.sys driver, part of the K7 Security Anti-Malware suite, allows a local low-privilege user to send crafted IOCTL requests to…published
- CVE-2025-497048.8100%Authenticated Code Injection RCE in Microsoft SharePoint
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | asp.net | eral product versions simultaneously. The webshell extracts ASP.NET machine keys, allowing the attackers to forge signed __VIEW |
| domain | litter.catbox.moe | cious DLL Network Indicators Network IoC Type Observed Role litter[.]catbox[.]moe Defanged hostname Payload-hosting and malware-delivery |
| domain | xn8xyt-drop.s3.wasabisys.com | ostname Payload-hosting and malware-delivery infrastructure xn8xyt-drop[.]s3[.]wasabisys[.]com Defanged hostname Cloud-storage endpoint used to retr |
| sha256 | 116ca4e88a1bcebb6c0da7fb431c8eca7b8ef3f9767194820c56091972ccac2c | y planning now. File Indicators SHA-256 Hash Classification 116ca4e88a1bcebb6c0da7fb431c8eca7b8ef3f9767194820c56091972ccac2c Warlock ransomware 155fb1cbdaea12c83ba92d18c88cf38bbc42bb68 |
| sha256 | 155fb1cbdaea12c83ba92d18c88cf38bbc42bb684f913ca0bc26fcf115426a55 | 431c8eca7b8ef3f9767194820c56091972ccac2c Warlock ransomware 155fb1cbdaea12c83ba92d18c88cf38bbc42bb684f913ca0bc26fcf115426a55 Warlock ransomware 1edb2c0b537cd95bbd5fc16321b4c38a6adf325c |
Full article714 words · extracted from cybersecuritynews.com · click to collapse
A China-nexus threat actor is continuing to exploit Microsoft SharePoint Server vulnerabilities to deploy Warlock ransomware, with recent attacks striking essential-service and public-sector organizations across Portuguese- and Spanish-speaking countries.
Symantec tracks the operator as Longlegs, while Microsoft uses Storm-2603; earlier activity has also been linked to CL-CRI-1040, CamoFei, and ChamelGang.
During the past two months, the campaign compromised at least four organizations: a water utility, a telecommunications provider, a regional government body, and a university spanning Europe, Africa, and Latin America.
Warlock surfaced in June 2025 and quickly gained attention after being deployed through the SharePoint “ToolShell” exploit chain. ToolShell combined CVE-2025-49704 and CVE-2025-49706, while subsequent bypasses were assigned CVE-2025-53770 and CVE-2025-53771.
CISA confirmed that the chain enabled unauthorized access to on-premises SharePoint servers, exposure of internal configurations, and remote code execution.
Warlock was among the ransomware payloads observed on compromised systems. Newer SharePoint flaws disclosed in 2026 have kept the attack surface relevant, with CISA warning of active exploitation affecting supported on-premises editions.
According to research published by Symantec, Longlegs typically plants an ASPX webshell in SharePoint’s LAYOUTS directory, targeting several product versions simultaneously.
The webshell extracts ASP.NET machine keys, allowing the attackers to forge signed __VIEWSTATE payloads and execute code inside the SharePoint application pool.
Follow-on malware is then loaded through DLL sideloading, while installers are retrieved from legitimate hosting services, including Catbox and Wasabi, helping malicious traffic resemble routine cloud activity.
In one critical-infrastructure intrusion, activity began on July 22, 2026, when a webshell appeared on a SharePoint server. The attackers later ran whoami, net user /domain, and nltest /domain_trusts, deployed sideloading pairs, and used NetExec for Active Directory discovery, credential spraying, and remote execution.
They also installed Microsoft-signed code-insiders.exe as a service and abused Visual Studio Code’s tunnel function, creating covert access through infrastructure that defenders may associate with legitimate administrators or developers.
Before encryption, Longlegs pushed an AV and EDR termination utility to at least 40 hosts in roughly two hours. Recent operations have used the signed but vulnerable K7RKScan driver, tracked as CVE-2025-1055, to terminate privileged processes from kernel space a bring-your-own-vulnerable-driver technique.
NIST says the flaw stems from missing authorization in the driver’s IOCTL handler and affects K7 Security Anti-Malware versions earlier than 23.0.0.10. Investigators cautioned that they did not conclusively identify the specific driver used in this intrusion.
Warlock followed almost immediately on at least 33 systems. The attackers placed run.exe, rune.exe, and the ransom note “how to restore your files.txt” in the compromised domain’s SYSVOL share.
Because SYSVOL replicates across domain controllers and is readable domain-wide, ordinary Distributed File System Replication helped deliver the payload broadly, turning trusted Active Directory infrastructure into a ransomware distribution channel.
The campaign shows why patching alone is insufficient after suspected SharePoint exploitation. Defenders should hunt for webshells and abnormal SharePoint worker-process behavior, rotate ASP.NET and IIS machine keys after removing persistence, enable AMSI in Full Mode, deploy EDR, restrict SharePoint’s internet exposure, and inspect suspicious ToolPane.aspx requests.
CISA additionally recommends placing any necessary public-facing deployment behind an authenticated Layer 7 proxy and blocking external access to Central Administration. For water, telecom, government, and education operators, delayed remediation can transform one exposed collaboration server into domain-wide operational disruption.
The targeting pattern may reflect vulnerable exposed servers or deliberate regional tasking, but either explanation demands urgent asset discovery, containment, and recovery planning now.
File Indicators
| SHA-256 Hash | Classification |
|---|---|
116ca4e88a1bcebb6c0da7fb431c8eca7b8ef3f9767194820c56091972ccac2c | Warlock ransomware |
155fb1cbdaea12c83ba92d18c88cf38bbc42bb684f913ca0bc26fcf115426a55 | Warlock ransomware |
1edb2c0b537cd95bbd5fc16321b4c38a6adf325ccc7b588ad6acc980b0463b60 | Malicious DLL |
206f27ae820783b7755bca89f83a0fe096dbb510018dd65b63fc80bd20c03261 | Malicious DLL |
27b7591cf9e1283010ca98fa5dbe970a73fee0d8cde277639924c144718db7c0 | Malicious DLL |
37f94fe1b4a106f02b6f74a69cbc05e69c17406f688beef4c9a045ffcbd2e65e | Suspicious file |
6d07f1232dc59b84038fd0b2e75fdd3d5b825882bb0dba9e6724b7b0823fa3ad | Warlock ransomware |
73c5268256c9da5488cd9e2b79013060ac321c7e54129344dc7b51e268af36ea | AV/EDR killer |
8b58f7811a2a2f2a5024220490473774f02759dd2dd904b5b9fabfbaae37125f | Warlock ransomware |
8ce8d8270ee9de02644530b8dd7fa78973b4a3b80f121e2c5f45ae68cce196f9 | Warlock ransomware |
9ceb01f8bf7d6dba2ae07f5bd6070de3ec67b5eb01f969b0ba85e74564fb83a7 | Suspicious file |
aaff04d84ef85353966aa4af186ff1254b72c068f33f802417b29dc23fb9f192 | Suspicious file |
ae9f7fce57c7b928e659dccf0e00fa79cd9cd61a106f18d4e03f92dc3a03c295 | Vulnerable driver |
c46825fcc0d1bf7a8b192facb176d6bf916c9dccfd6fa994be691e3b0e585f4e | Malicious DLL |
e14240bac8277b0f6dd4d29ab5da20d246bcccae647e5fe8d19cdae7fe471b20 | Malicious DLL |
e3204b05e2f3a29bb6e6fcc21dda77d7cd31dfa755c21da0aa8661b5619ee0a1 | Suspicious file |
eea631b5f7125239db0811e4682c2316ead69f9822e02d94fb5d8bf0d2faebed | Suspicious file |
f7269f80f81e99d06a590d7ab374e12fdf7e5f55a02c2a46c342d670f8519fdf | Suspicious file |
fb3846c9ac53d1b841ada3a6b1091153fea41a169cb44fe0084097d1f4d45984 | Malicious DLL |
Network Indicators
| Network IoC | Type | Observed Role |
|---|---|---|
litter[.]catbox[.]moe | Defanged hostname | Payload-hosting and malware-delivery infrastructure |
xn8xyt-drop[.]s3[.]wasabisys[.]com | Defanged hostname | Cloud-storage endpoint used to retrieve a malicious MSI package |
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup into your SOC
Guru Baranhttps://cybersecuritynews.com
Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.