Full Report
New data from Symantec observed that the China-nexus group behind Warlock ransomware, tracked as Longlegs or Storm-2603, has... The post Symantec reports Warlock ransomware group targets water, telecom, government organizations through SharePoint flaws appeared first on Industrial Cyber.
Analysis Summary
# Threat Actor: Longlegs (Warlock Ransomware Group)
## Attribution & Identity
* **Name/Alias:** Longlegs, Storm-2603, Warlock Ransomware Group.
* **Attribution:** China-nexus threat actor.
* **Associated Groups:** Tracked as Storm-2603 by Microsoft; identified by Symantec as the primary operator of Warlock ransomware.
## Activity Summary
The group emerged in June 2025 and gained notoriety for exploiting zero-day vulnerabilities in Microsoft SharePoint. In late 2026, Symantec reported a surge in activity where the group targeted critical infrastructure and public service organizations across Europe, Africa, and Latin America. Notably, the group is capable of rapid lateral movement, once disabling security software on 40 hosts within two hours to facilitate ransomware deployment.
## Tactics, Techniques & Procedures
* **Initial Access:** Exploitation of on-premises Microsoft SharePoint Server vulnerabilities (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771).
* **Webshell Deployment:** Dropping webshells into the SharePoint `LAYOUTS` directory to harvest ASP.NET machine keys.
* **Execution:** Forging validly signed payloads to achieve remote code execution (RCE) via the SharePoint application pool.
* **Persistence & Remote Access:** Abuse of Visual Studio Code’s built-in tunnel feature (`code-insiders.exe`) to establish covert remote access.
* **Lateral Movement:** Staging ransomware in the domain’s `SYSVOL` share to leverage legitimate domain replication for payload distribution.
* **Defense Evasion:** Use of DLL side-loading and specialized tools to disable security/antivirus software.
* **Living-off-the-Land (LotL):** Heavy reliance on built-in Windows administrative tools and legitimate binaries to blend in with normal network traffic.
## Targeting
* **Sectors:** Water utilities, Telecommunications, Government (regional bodies), Higher Education (Universities), and Critical Infrastructure.
* **Geography:** Portuguese- and Spanish-speaking countries in Europe, Africa, and Latin America.
* **Victims:** At least four major organizations recently, including a water utility and a telecom provider.
## Tools & Infrastructure
* **Malware:** Warlock Ransomware, custom webshells, "ToolShell" exploit kit.
* **Legitimate Software Abuse:** Visual Studio Code (tunneling), SharePoint Server, Windows SYSVOL replication.
* **Infrastructure:** Uses compromised credentials and administrative access; C2 traffic is disguised via Visual Studio Code tunneling to appear as legitimate developer activity.
## Implications
Longlegs represents a sophisticated China-nexus threat that bridges the gap between traditional espionage-style exploitation (SharePoint zero-days) and disruptive financial or operational impact (ransomware). Their ability to exploit internet-facing enterprise software and rapidly weaponize administrative features (like SYSVOL and VS Code tunnels) poses a significant risk to critical infrastructure reliability and data integrity.
## Mitigations
* **Patch Management:** Prioritize immediate patching of Microsoft SharePoint Server, specifically addressing the "ToolShell" vulnerabilities and those identified in the July 2026 CISA advisory.
* **Endpoint Defense:** Monitor for the unauthorized execution of `code-insiders.exe` and other Visual Studio Code binaries used for tunneling.
* **Identity Security:** Implement multi-factor authentication (MFA) and monitor for anomalous behavior involving administrative credentials and the SharePoint application pool.
* **Network Auditing:** Audit the `SYSVOL` share for unauthorized file staging and monitor for sudden, large-scale security software disabling events across the domain.