The China-nexus operators behind Warlock ransomware are still getting in through on-premises Microsoft SharePoint Server, more than a year after the ToolShell zero-days made them notorious. In research published on 1 October 2026, Symantec and Carbon Black's Threat Hunter Team said the group it tracks as Longlegs (aka Storm-2603) attacked at least four organisations in the past two months in Portuguese- and Spanish-speaking countries across Europe, Africa and Latin America: a water utility, a telecommunications provider, a regional government body and a university. In one critical-infrastructure intrusion the attackers disabled security tooling on at least 40 hosts in roughly two hours and then used ordinary Active Directory SYSVOL replication to land Warlock on at least 33 machines. Any organisation still running internet-reachable SharePoint Server should treat this as a prompt to verify patch state, hunt for machine-key harvesters and lock down SYSVOL now.

Who is Longlegs?

Symantec says Warlock is developed by a China-nexus threat actor it calls Longlegs, also tracked as Storm-2603, and that it has previously tied the group to older activity clusters known as CL-CRI-1040, CamoFei and ChamelGang. Warlock emerged in June 2025 and came to prominence weeks later, when attackers deploying it were found exploiting the SharePoint "ToolShell" zero-days: CVE-2025-49704, CVE-2025-49706, CVE-2025-53770 and CVE-2025-53771.

Symantec assesses that those flaws "likely remain in the group's arsenal", alongside newer SharePoint vulnerabilities that CISA warned about in July 2026. That CISA alert, last revised on 26 August 2026, lists six actively exploited on-premises SharePoint flaws (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, CVE-2026-58644, CVE-2026-50522 and CVE-2026-55040) affecting Subscription Edition, 2019 and 2016. Symantec does not say which specific CVE was used in each of the recent intrusions.

Historically, Warlock activity has been seen against organisations in the United States, Brazil, India, Russia, Taiwan and Japan. Symantec describes the recent concentration on Portuguese- and Spanish-speaking countries as noteworthy, and says it may reflect either opportunistic targeting of exposed, vulnerable SharePoint servers or more deliberate tasking.

Attack mechanics: from SharePoint machine keys to domain-wide ransomware

Initial access and the machine-key webshell

According to Symantec, Longlegs drops a webshell into the SharePoint LAYOUTS directory for multiple SharePoint versions at once, so that it works regardless of which version is installed. The webshell's job is to harvest the farm's ASP.NET machine keys. With those keys the attackers forge a validly signed payload that achieves remote code execution inside the SharePoint application pool. In the intrusion Symantec walked through, the webshell was written as layout2sp.aspx via a PowerShell [IO.File]::WriteAllBytes call into the web server extensions\14\template\layouts path.

On 28 July the exploitation chain proper began: the SharePoint host repeatedly ran a PowerShell command that loads the System.Workflow.ComponentModel assembly, which Symantec says provides the deserialization gadget used to turn a forged, machine-key-signed __VIEWSTATE payload into arbitrary code execution. The practical consequence for defenders is that patching alone does not evict an actor that already holds the machine keys; the keys must be rotated after the harvesting artefacts are removed.

Defence evasion: DLL sideloading and a vulnerable driver

The group uses DLL sideloading to load malicious code into memory. Symantec recorded sideloading pairs such as ssvagent.exe and logger.exe with gsdll64.dll.tmp and doexeloc.dll.tmp, and doexe.exe with doexeloc.dll, the latter dropped directly by the SharePoint worker process. Follow-on payloads are pulled from legitimate file-hosting services, catbox[.]moe and wasabisys[.]com, to blend in with normal traffic.

To blind endpoint protection before deploying ransomware, Longlegs has abused K7RKScan, a signed but vulnerable driver tracked as CVE-2025-1055. NVD describes the flaw as missing access control in the K7RKScan.sys IOCTL handler that lets a local low-privilege user terminate processes running with administrative or SYSTEM privileges. This is a classic bring-your-own-vulnerable-driver (BYOVD) technique. In the specific intrusion Symantec detailed, the AV/EDR killer (a.exe) likely leveraged a vulnerable driver, but Symantec says the identity of that driver "remains unknown"; K7RKScan was used in other recent attacks by the group.

Living off the land and VS Code tunnels

Reconnaissance relied on built-in tools: net user /domain, whoami and nltest /domain_trusts. The attackers repeatedly added a domain account named SPSEPRDSetup to the local Administrators group on further hosts, a name Symantec believes was chosen to masquerade as a SharePoint setup service account. They then ran NetExec (nxc.exe), the open-source successor to CrackMapExec, for Active Directory enumeration, credential spraying and remote command execution.

For persistent remote access the group did not use a bespoke RAT. Instead it installed the Microsoft-signed Visual Studio Code Insiders binary as a tunnel service from C:\Windows\debug\, so that remote access relays through Microsoft's own infrastructure and resembles traffic from developer or administrator workstations.

Ransomware delivery through SYSVOL replication

In the final phase, the attackers mapped an internal share, copied a tool set from an av folder to C:\Users\Public and launched a.exe. The AV/EDR killer then ran on at least 40 further hosts within about two hours. Warlock followed almost immediately: two binaries, run.exe and rune.exe, and a ransom note titled how to restore your files.txt appeared on at least 33 hosts. The payloads were staged in SYSVOL\[domain]\scripts\run. On three hosts, telemetry showed the DFS Replication service (dfsrs.exe) as the parent that delivered run.exe and rune.exe, confirming that ordinary SYSVOL replication carried the ransomware rather than a separate push mechanism.

Intrusion timeline (critical-infrastructure victim, 2026)

DateActivity reported by Symantec
22 JulyWebshell layout2sp.aspx written to the SharePoint LAYOUTS directory on Computer 1.
24 Julynet user /domain and whoami on a second SharePoint host; staging files deleted; sideloading pairs deployed; nltest /domain_trusts run.
27 JulyOutbound PowerShell request to an oastify.com (Burp Collaborator) subdomain embedding the target's domain name.
28 JulyWebshell re-tested; System.Workflow.ComponentModel gadget loading for forged __VIEWSTATE RCE; three MSI payloads fetched via msiexec from catbox and Wasabi.
28–29 JulySPSEPRDSetup added to local Administrators on three hosts; VS Code Insiders tunnel installed as a service; NetExec run.
30–31 JulySideloaded doexe.exe/doexeloc.dll pair keeps running on Computer 1.
31 July (early hours)AV/EDR killer pushed to 40+ hosts in about two hours; Warlock (run.exe, rune.exe) delivered via SYSVOL to 33+ hosts.

MITRE ATT&CK mapping

The mapping below is CyberSecureToday's analysis of the behaviours Symantec documented.

TacticTechniqueObserved behaviour
Initial AccessT1190 Exploit Public-Facing ApplicationExploitation of on-premises SharePoint Server
PersistenceT1505.003 Web Shelllayout2sp.aspx in SharePoint LAYOUTS
Credential AccessT1552.001 Credentials In FilesHarvesting ASP.NET machine keys from the farm
ExecutionT1059.001 PowerShellWebshell drop, gadget loading, oastify canary request
Defense EvasionT1218.007 Msiexecmsiexec /q /i from catbox and Wasabi URLs
Defense EvasionT1574 Hijack Execution Flow (DLL side-loading)doexe.exe + doexeloc.dll; ssvagent.exe/logger.exe pairs
Defense EvasionT1562.001 Disable or Modify ToolsBYOVD AV/EDR killer (a.exe); K7RKScan in other attacks
Defense EvasionT1070.004 File DeletionRemoval of early staging files
DiscoveryT1087.002 Domain Account / T1033 System Owner/Usernet user /domain, whoami
DiscoveryT1482 Domain Trust Discoverynltest /domain_trusts
PersistenceT1098 Account Manipulation; T1036 MasqueradingSPSEPRDSetup added to local Administrators
Command and ControlT1219 Remote Access Software; T1543.003 Windows Servicecode-insiders.exe tunnel service install
Credential AccessT1110.003 Password SprayingNetExec credential spraying
Lateral MovementT1021.002 SMB/Windows Admin Shares; T1570 Lateral Tool Transfernet use + copy from internal share; SYSVOL staging
ImpactT1486 Data Encrypted for ImpactWarlock ransomware on 33+ hosts

Indicators of compromise

The table reproduces a subset of Symantec's published indicators. Symantec also lists seven hashes it labels "Suspicious file"; see the original report for the complete list.

SHA-256 / indicatorSymantec label
116ca4e88a1bcebb6c0da7fb431c8eca7b8ef3f9767194820c56091972ccac2cWarlock
155fb1cbdaea12c83ba92d18c88cf38bbc42bb684f913ca0bc26fcf115426a55Warlock
6d07f1232dc59b84038fd0b2e75fdd3d5b825882bb0dba9e6724b7b0823fa3adWarlock
8b58f7811a2a2f2a5024220490473774f02759dd2dd904b5b9fabfbaae37125fWarlock
8ce8d8270ee9de02644530b8dd7fa78973b4a3b80f121e2c5f45ae68cce196f9Warlock
73c5268256c9da5488cd9e2b79013060ac321c7e54129344dc7b51e268af36eaAV/EDR Killer
ae9f7fce57c7b928e659dccf0e00fa79cd9cd61a106f18d4e03f92dc3a03c295Vulnerable driver
1edb2c0b537cd95bbd5fc16321b4c38a6adf325ccc7b588ad6acc980b0463b60Malicious DLL
206f27ae820783b7755bca89f83a0fe096dbb510018dd65b63fc80bd20c03261Malicious DLL
27b7591cf9e1283010ca98fa5dbe970a73fee0d8cde277639924c144718db7c0Malicious DLL
c46825fcc0d1bf7a8b192facb176d6bf916c9dccfd6fa994be691e3b0e585f4eMalicious DLL
e14240bac8277b0f6dd4d29ab5da20d246bcccae647e5fe8d19cdae7fe471b20Malicious DLL
fb3846c9ac53d1b841ada3a6b1091153fea41a169cb44fe0084097d1f4d45984Malicious DLL
litter[.]catbox[.]moeNetwork IOC
xn8xyt-drop[.]s3[.]wasabisys[.]comNetwork IOC

Payload URLs recorded in the intrusion: hxxps://litter.catbox[.]moe/6f5tdt.msi, hxxps://s3.wasabisys[.]com/fortifs/vamd64.msi and hxxps://xn8xyt-drop.s3.wasabisys[.]com/xn8xyt.msi. File and account artefacts worth hunting: layout2sp.aspx, doexe.exe, doexeloc.dll, gsdll64.dll.tmp, ssvagent.exe and logger.exe under C:\Windows\System32\0409\, C:\Users\Public\a.exe, run.exe, rune.exe, how to restore your files.txt, and the account SPSEPRDSetup.

Defensive playbook

  1. Patch and reduce exposure of SharePoint Server. Confirm every on-premises farm has the current security update installed successfully. CISA advises against exposing SharePoint directly to the internet; where exposure is unavoidable, place it behind a Layer 7 reverse proxy that enforces authentication, and block external access to Central Administration.
  2. Enable AMSI in Full Mode for each SharePoint web application, per Microsoft's guidance, and act on the AMSI and Defender detections CISA lists (for example Exploit:Script/ToolPaneAuthBypass.A and Backdoor:MSIL/LeakFang.A!dha).
  3. Hunt first, then rotate machine keys. CISA's guidance is explicit: remove intrusion artefacts, including machine-key harvesters, before rotating IIS/ASP.NET machine keys, or they will be stolen again.
  4. Block the published driver and killer hashes through your EDR or application control, and confirm the Microsoft vulnerable driver blocklist is enabled.
  5. Treat SYSVOL as a high-value write path. Alert on any new .exe, .dll or .msi under SYSVOL\*\scripts, and on files written by dfsrs.exe that are subsequently executed.
  6. Inventory remote-access tooling. Flag VS Code or VS Code Insiders running as a Windows service or with the tunnel argument on servers, and restrict egress to tunnel relays where developer tunnels are not sanctioned.
  7. Restrict local admin changes. Alert on additions to local Administrators, especially service-account-style names, and on NetExec execution or credential-spraying patterns.

Check for LAYOUTS webshells and the SharePoint build

# Run in the SharePoint Management Shell on each farm server
(Get-SPFarm).BuildVersion

# Recently written .aspx files in every LAYOUTS hive (14, 15, 16)
Get-ChildItem "C:\Program Files\Common Files\microsoft shared\Web Server Extensions\*\TEMPLATE\LAYOUTS" -Filter *.aspx -Recurse -ErrorAction SilentlyContinue |
  Where-Object { $_.LastWriteTime -gt (Get-Date).AddDays(-120) -or $_.Name -eq 'layout2sp.aspx' } |
  Select-Object FullName, LastWriteTime

Sweep SYSVOL and services

# Executables or installers staged in SYSVOL scripts
Get-ChildItem "\\$env:USERDNSDOMAIN\SYSVOL\$env:USERDNSDOMAIN\scripts" -Recurse -Include *.exe,*.dll,*.msi -ErrorAction SilentlyContinue |
  Select-Object FullName, Length, LastWriteTime

# VS Code / VS Code Insiders registered as a Windows service
Get-CimInstance Win32_Service | Where-Object { $_.PathName -match 'code(-insiders)?\.exe' } |
  Select-Object Name, State, PathName

# Vulnerable driver blocklist (1 = enabled)
Get-ItemProperty 'HKLM:\SYSTEM\CurrentControlSet\Control\CI\Config' -Name VulnerableDriverBlocklistEnable -ErrorAction SilentlyContinue

Microsoft Defender XDR hunting starting points

// Starting point: behaviours documented by Symantec in the Warlock intrusion
DeviceProcessEvents
| where Timestamp > ago(30d)
| where (FileName in~ ("code-insiders.exe","code.exe") and ProcessCommandLine has "tunnel" and ProcessCommandLine has "service")
    or FileName =~ "nxc.exe"
    or (FileName =~ "nltest.exe" and ProcessCommandLine has "/domain_trusts")
    or (ProcessCommandLine has "localgroup" and ProcessCommandLine has "SPSEPRDSetup")
    or (FileName =~ "msiexec.exe" and ProcessCommandLine has_any ("catbox.moe","wasabisys.com"))
    or (ProcessCommandLine has "System.Workflow.ComponentModel" and InitiatingProcessFileName =~ "w3wp.exe")
| project Timestamp, DeviceName, AccountName, FileName, ProcessCommandLine, InitiatingProcessFileName

// Files delivered by DFS Replication into SYSVOL scripts
DeviceFileEvents
| where Timestamp > ago(30d)
| where InitiatingProcessFileName =~ "dfsrs.exe" and FolderPath has @"\SYSVOL\" and FolderPath has @"\scripts\"
| where FileName endswith ".exe" or FileName endswith ".dll"
| project Timestamp, DeviceName, FolderPath, FileName, SHA256

These queries are starting points built only from artefacts Symantec published; expect to tune them for legitimate developer tunnels and administrative tooling in your environment.

Why this matters

Longlegs is a reminder that a high-profile exploit chain does not stop being useful to attackers once the headlines fade. Symantec's conclusion is that ToolShell and related SharePoint vulnerabilities "remain a viable initial access route" against deployments that have not been patched or otherwise mitigated. For water and telecom operators in particular, the speed of the final phase is the key lesson: once machine keys and domain credentials were in hand, it took the attackers about two hours to disable protection across the estate, and Warlock began appearing almost as soon as each host was blinded, delivered by replication infrastructure every Windows domain already trusts.