The China-nexus operators behind Warlock ransomware are still getting in through on-premises Microsoft SharePoint Server, more than a year after the ToolShell zero-days made them notorious. In research published on 1 October 2026, Symantec and Carbon Black's Threat Hunter Team said the group it tracks as Longlegs (aka Storm-2603) attacked at least four organisations in the past two months in Portuguese- and Spanish-speaking countries across Europe, Africa and Latin America: a water utility, a telecommunications provider, a regional government body and a university. In one critical-infrastructure intrusion the attackers disabled security tooling on at least 40 hosts in roughly two hours and then used ordinary Active Directory SYSVOL replication to land Warlock on at least 33 machines. Any organisation still running internet-reachable SharePoint Server should treat this as a prompt to verify patch state, hunt for machine-key harvesters and lock down SYSVOL now.
Who is Longlegs?
Symantec says Warlock is developed by a China-nexus threat actor it calls Longlegs, also tracked as Storm-2603, and that it has previously tied the group to older activity clusters known as CL-CRI-1040, CamoFei and ChamelGang. Warlock emerged in June 2025 and came to prominence weeks later, when attackers deploying it were found exploiting the SharePoint "ToolShell" zero-days: CVE-2025-49704, CVE-2025-49706, CVE-2025-53770 and CVE-2025-53771.
Symantec assesses that those flaws "likely remain in the group's arsenal", alongside newer SharePoint vulnerabilities that CISA warned about in July 2026. That CISA alert, last revised on 26 August 2026, lists six actively exploited on-premises SharePoint flaws (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, CVE-2026-58644, CVE-2026-50522 and CVE-2026-55040) affecting Subscription Edition, 2019 and 2016. Symantec does not say which specific CVE was used in each of the recent intrusions.
Historically, Warlock activity has been seen against organisations in the United States, Brazil, India, Russia, Taiwan and Japan. Symantec describes the recent concentration on Portuguese- and Spanish-speaking countries as noteworthy, and says it may reflect either opportunistic targeting of exposed, vulnerable SharePoint servers or more deliberate tasking.
Attack mechanics: from SharePoint machine keys to domain-wide ransomware
Initial access and the machine-key webshell
According to Symantec, Longlegs drops a webshell into the SharePoint LAYOUTS directory for multiple SharePoint versions at once, so that it works regardless of which version is installed. The webshell's job is to harvest the farm's ASP.NET machine keys. With those keys the attackers forge a validly signed payload that achieves remote code execution inside the SharePoint application pool. In the intrusion Symantec walked through, the webshell was written as layout2sp.aspx via a PowerShell [IO.File]::WriteAllBytes call into the web server extensions\14\template\layouts path.
On 28 July the exploitation chain proper began: the SharePoint host repeatedly ran a PowerShell command that loads the System.Workflow.ComponentModel assembly, which Symantec says provides the deserialization gadget used to turn a forged, machine-key-signed __VIEWSTATE payload into arbitrary code execution. The practical consequence for defenders is that patching alone does not evict an actor that already holds the machine keys; the keys must be rotated after the harvesting artefacts are removed.
Defence evasion: DLL sideloading and a vulnerable driver
The group uses DLL sideloading to load malicious code into memory. Symantec recorded sideloading pairs such as ssvagent.exe and logger.exe with gsdll64.dll.tmp and doexeloc.dll.tmp, and doexe.exe with doexeloc.dll, the latter dropped directly by the SharePoint worker process. Follow-on payloads are pulled from legitimate file-hosting services, catbox[.]moe and wasabisys[.]com, to blend in with normal traffic.
To blind endpoint protection before deploying ransomware, Longlegs has abused K7RKScan, a signed but vulnerable driver tracked as CVE-2025-1055. NVD describes the flaw as missing access control in the K7RKScan.sys IOCTL handler that lets a local low-privilege user terminate processes running with administrative or SYSTEM privileges. This is a classic bring-your-own-vulnerable-driver (BYOVD) technique. In the specific intrusion Symantec detailed, the AV/EDR killer (a.exe) likely leveraged a vulnerable driver, but Symantec says the identity of that driver "remains unknown"; K7RKScan was used in other recent attacks by the group.
Living off the land and VS Code tunnels
Reconnaissance relied on built-in tools: net user /domain, whoami and nltest /domain_trusts. The attackers repeatedly added a domain account named SPSEPRDSetup to the local Administrators group on further hosts, a name Symantec believes was chosen to masquerade as a SharePoint setup service account. They then ran NetExec (nxc.exe), the open-source successor to CrackMapExec, for Active Directory enumeration, credential spraying and remote command execution.
For persistent remote access the group did not use a bespoke RAT. Instead it installed the Microsoft-signed Visual Studio Code Insiders binary as a tunnel service from C:\Windows\debug\, so that remote access relays through Microsoft's own infrastructure and resembles traffic from developer or administrator workstations.
Ransomware delivery through SYSVOL replication
In the final phase, the attackers mapped an internal share, copied a tool set from an av folder to C:\Users\Public and launched a.exe. The AV/EDR killer then ran on at least 40 further hosts within about two hours. Warlock followed almost immediately: two binaries, run.exe and rune.exe, and a ransom note titled how to restore your files.txt appeared on at least 33 hosts. The payloads were staged in SYSVOL\[domain]\scripts\run. On three hosts, telemetry showed the DFS Replication service (dfsrs.exe) as the parent that delivered run.exe and rune.exe, confirming that ordinary SYSVOL replication carried the ransomware rather than a separate push mechanism.
Intrusion timeline (critical-infrastructure victim, 2026)
| Date | Activity reported by Symantec |
|---|---|
| 22 July | Webshell layout2sp.aspx written to the SharePoint LAYOUTS directory on Computer 1. |
| 24 July | net user /domain and whoami on a second SharePoint host; staging files deleted; sideloading pairs deployed; nltest /domain_trusts run. |
| 27 July | Outbound PowerShell request to an oastify.com (Burp Collaborator) subdomain embedding the target's domain name. |
| 28 July | Webshell re-tested; System.Workflow.ComponentModel gadget loading for forged __VIEWSTATE RCE; three MSI payloads fetched via msiexec from catbox and Wasabi. |
| 28–29 July | SPSEPRDSetup added to local Administrators on three hosts; VS Code Insiders tunnel installed as a service; NetExec run. |
| 30–31 July | Sideloaded doexe.exe/doexeloc.dll pair keeps running on Computer 1. |
| 31 July (early hours) | AV/EDR killer pushed to 40+ hosts in about two hours; Warlock (run.exe, rune.exe) delivered via SYSVOL to 33+ hosts. |
MITRE ATT&CK mapping
The mapping below is CyberSecureToday's analysis of the behaviours Symantec documented.
| Tactic | Technique | Observed behaviour |
|---|---|---|
| Initial Access | T1190 Exploit Public-Facing Application | Exploitation of on-premises SharePoint Server |
| Persistence | T1505.003 Web Shell | layout2sp.aspx in SharePoint LAYOUTS |
| Credential Access | T1552.001 Credentials In Files | Harvesting ASP.NET machine keys from the farm |
| Execution | T1059.001 PowerShell | Webshell drop, gadget loading, oastify canary request |
| Defense Evasion | T1218.007 Msiexec | msiexec /q /i from catbox and Wasabi URLs |
| Defense Evasion | T1574 Hijack Execution Flow (DLL side-loading) | doexe.exe + doexeloc.dll; ssvagent.exe/logger.exe pairs |
| Defense Evasion | T1562.001 Disable or Modify Tools | BYOVD AV/EDR killer (a.exe); K7RKScan in other attacks |
| Defense Evasion | T1070.004 File Deletion | Removal of early staging files |
| Discovery | T1087.002 Domain Account / T1033 System Owner/User | net user /domain, whoami |
| Discovery | T1482 Domain Trust Discovery | nltest /domain_trusts |
| Persistence | T1098 Account Manipulation; T1036 Masquerading | SPSEPRDSetup added to local Administrators |
| Command and Control | T1219 Remote Access Software; T1543.003 Windows Service | code-insiders.exe tunnel service install |
| Credential Access | T1110.003 Password Spraying | NetExec credential spraying |
| Lateral Movement | T1021.002 SMB/Windows Admin Shares; T1570 Lateral Tool Transfer | net use + copy from internal share; SYSVOL staging |
| Impact | T1486 Data Encrypted for Impact | Warlock ransomware on 33+ hosts |
Indicators of compromise
The table reproduces a subset of Symantec's published indicators. Symantec also lists seven hashes it labels "Suspicious file"; see the original report for the complete list.
| SHA-256 / indicator | Symantec label |
|---|---|
116ca4e88a1bcebb6c0da7fb431c8eca7b8ef3f9767194820c56091972ccac2c | Warlock |
155fb1cbdaea12c83ba92d18c88cf38bbc42bb684f913ca0bc26fcf115426a55 | Warlock |
6d07f1232dc59b84038fd0b2e75fdd3d5b825882bb0dba9e6724b7b0823fa3ad | Warlock |
8b58f7811a2a2f2a5024220490473774f02759dd2dd904b5b9fabfbaae37125f | Warlock |
8ce8d8270ee9de02644530b8dd7fa78973b4a3b80f121e2c5f45ae68cce196f9 | Warlock |
73c5268256c9da5488cd9e2b79013060ac321c7e54129344dc7b51e268af36ea | AV/EDR Killer |
ae9f7fce57c7b928e659dccf0e00fa79cd9cd61a106f18d4e03f92dc3a03c295 | Vulnerable driver |
1edb2c0b537cd95bbd5fc16321b4c38a6adf325ccc7b588ad6acc980b0463b60 | Malicious DLL |
206f27ae820783b7755bca89f83a0fe096dbb510018dd65b63fc80bd20c03261 | Malicious DLL |
27b7591cf9e1283010ca98fa5dbe970a73fee0d8cde277639924c144718db7c0 | Malicious DLL |
c46825fcc0d1bf7a8b192facb176d6bf916c9dccfd6fa994be691e3b0e585f4e | Malicious DLL |
e14240bac8277b0f6dd4d29ab5da20d246bcccae647e5fe8d19cdae7fe471b20 | Malicious DLL |
fb3846c9ac53d1b841ada3a6b1091153fea41a169cb44fe0084097d1f4d45984 | Malicious DLL |
litter[.]catbox[.]moe | Network IOC |
xn8xyt-drop[.]s3[.]wasabisys[.]com | Network IOC |
Payload URLs recorded in the intrusion: hxxps://litter.catbox[.]moe/6f5tdt.msi, hxxps://s3.wasabisys[.]com/fortifs/vamd64.msi and hxxps://xn8xyt-drop.s3.wasabisys[.]com/xn8xyt.msi. File and account artefacts worth hunting: layout2sp.aspx, doexe.exe, doexeloc.dll, gsdll64.dll.tmp, ssvagent.exe and logger.exe under C:\Windows\System32\0409\, C:\Users\Public\a.exe, run.exe, rune.exe, how to restore your files.txt, and the account SPSEPRDSetup.
Defensive playbook
- Patch and reduce exposure of SharePoint Server. Confirm every on-premises farm has the current security update installed successfully. CISA advises against exposing SharePoint directly to the internet; where exposure is unavoidable, place it behind a Layer 7 reverse proxy that enforces authentication, and block external access to Central Administration.
- Enable AMSI in Full Mode for each SharePoint web application, per Microsoft's guidance, and act on the AMSI and Defender detections CISA lists (for example
Exploit:Script/ToolPaneAuthBypass.AandBackdoor:MSIL/LeakFang.A!dha). - Hunt first, then rotate machine keys. CISA's guidance is explicit: remove intrusion artefacts, including machine-key harvesters, before rotating IIS/ASP.NET machine keys, or they will be stolen again.
- Block the published driver and killer hashes through your EDR or application control, and confirm the Microsoft vulnerable driver blocklist is enabled.
- Treat SYSVOL as a high-value write path. Alert on any new
.exe,.dllor.msiunderSYSVOL\*\scripts, and on files written bydfsrs.exethat are subsequently executed. - Inventory remote-access tooling. Flag VS Code or VS Code Insiders running as a Windows service or with the
tunnelargument on servers, and restrict egress to tunnel relays where developer tunnels are not sanctioned. - Restrict local admin changes. Alert on additions to local Administrators, especially service-account-style names, and on NetExec execution or credential-spraying patterns.
Check for LAYOUTS webshells and the SharePoint build
# Run in the SharePoint Management Shell on each farm server
(Get-SPFarm).BuildVersion
# Recently written .aspx files in every LAYOUTS hive (14, 15, 16)
Get-ChildItem "C:\Program Files\Common Files\microsoft shared\Web Server Extensions\*\TEMPLATE\LAYOUTS" -Filter *.aspx -Recurse -ErrorAction SilentlyContinue |
Where-Object { $_.LastWriteTime -gt (Get-Date).AddDays(-120) -or $_.Name -eq 'layout2sp.aspx' } |
Select-Object FullName, LastWriteTime
Sweep SYSVOL and services
# Executables or installers staged in SYSVOL scripts
Get-ChildItem "\\$env:USERDNSDOMAIN\SYSVOL\$env:USERDNSDOMAIN\scripts" -Recurse -Include *.exe,*.dll,*.msi -ErrorAction SilentlyContinue |
Select-Object FullName, Length, LastWriteTime
# VS Code / VS Code Insiders registered as a Windows service
Get-CimInstance Win32_Service | Where-Object { $_.PathName -match 'code(-insiders)?\.exe' } |
Select-Object Name, State, PathName
# Vulnerable driver blocklist (1 = enabled)
Get-ItemProperty 'HKLM:\SYSTEM\CurrentControlSet\Control\CI\Config' -Name VulnerableDriverBlocklistEnable -ErrorAction SilentlyContinue
Microsoft Defender XDR hunting starting points
// Starting point: behaviours documented by Symantec in the Warlock intrusion
DeviceProcessEvents
| where Timestamp > ago(30d)
| where (FileName in~ ("code-insiders.exe","code.exe") and ProcessCommandLine has "tunnel" and ProcessCommandLine has "service")
or FileName =~ "nxc.exe"
or (FileName =~ "nltest.exe" and ProcessCommandLine has "/domain_trusts")
or (ProcessCommandLine has "localgroup" and ProcessCommandLine has "SPSEPRDSetup")
or (FileName =~ "msiexec.exe" and ProcessCommandLine has_any ("catbox.moe","wasabisys.com"))
or (ProcessCommandLine has "System.Workflow.ComponentModel" and InitiatingProcessFileName =~ "w3wp.exe")
| project Timestamp, DeviceName, AccountName, FileName, ProcessCommandLine, InitiatingProcessFileName
// Files delivered by DFS Replication into SYSVOL scripts
DeviceFileEvents
| where Timestamp > ago(30d)
| where InitiatingProcessFileName =~ "dfsrs.exe" and FolderPath has @"\SYSVOL\" and FolderPath has @"\scripts\"
| where FileName endswith ".exe" or FileName endswith ".dll"
| project Timestamp, DeviceName, FolderPath, FileName, SHA256
These queries are starting points built only from artefacts Symantec published; expect to tune them for legitimate developer tunnels and administrative tooling in your environment.
Why this matters
Longlegs is a reminder that a high-profile exploit chain does not stop being useful to attackers once the headlines fade. Symantec's conclusion is that ToolShell and related SharePoint vulnerabilities "remain a viable initial access route" against deployments that have not been patched or otherwise mitigated. For water and telecom operators in particular, the speed of the final phase is the key lesson: once machine keys and domain credentials were in hand, it took the attackers about two hours to disable protection across the estate, and Warlock began appearing almost as soon as each host was blinded, delivered by replication infrastructure every Windows domain already trusts.



