Full Report
China-nexus group behind Warlock is still exploiting SharePoint vulnerabilities, attacking organizations in Portuguese and Spanish-speaking countries, hitting critical infrastructure, government, and education organizations.
Analysis Summary
# Threat Actor: Longlegs
## Attribution & Identity
* **Name/Alias:** Longlegs (Symantec)
* **Known Aliases:** Storm-2603 (Microsoft), CL-CRI-1040, CamoFei, ChamelGang.
* **Association:** China-nexus threat actor.
## Activity Summary
Longlegs has been highly active throughout 2025 and 2026, gaining notoriety for the exploitation of zero-day vulnerabilities in Microsoft SharePoint. In late 2026, the group conducted a concentrated campaign against Portuguese- and Spanish-speaking organizations. Notable recent operations involved attacking at least four organizations within a two-month window, including critical infrastructure entities, where they successfully deployed Warlock ransomware across dozens of hosts within hours of initial access.
## Tactics, Techniques & Procedures
* **Initial Access:** Exploitation of on-premises Microsoft SharePoint vulnerabilities (e.g., "ToolShell" exploit chain).
* **Persistence & Execution:** Drops webshells into SharePoint LAYOUTS directories; harvests ASP.NET machine keys to forge signed payloads for Remote Code Execution (RCE).
* **Defense Evasion:**
* **BYOVD (Bring Your Own Vulnerable Driver):** Abuses the signed but vulnerable **K7RKScan** driver to terminate security processes at the kernel level.
* **DLL Sideloading:** Loads malicious code into memory via legitimate processes.
* **Lateral Movement & Deployment:** Stages ransomware payloads in the domain's **SYSVOL** share to leverage automatic domain replication for mass deployment.
* **Command & Control (C2):** Abuses **Visual Studio Code's tunneling feature** (code-insiders.exe) to establish covert remote access that mimics developer traffic.
* **Living off the Land:** Extensive use of native Windows tools for reconnaissance and command execution.
**MITRE ATT&CK IDs:**
* **T1190:** Exploit Public-Facing Application (SharePoint)
* **T1059.003:** Command and Scripting Interpreter: Windows Command Shell
* **T1574.002:** Hijack Execution Flow: DLL Side-Loading
* **T1068:** Exploitation for Privilege Escalation
* **T1562.001:** Impair Defenses: Disable or Modify Tools (BYOVD)
* **T1608.005:** Stage Capabilities: Link Target (SYSVOL replication)
* **T1567:** Exfiltration Over Web Service (Cloud storage abuse)
## Targeting
* **Sectors:** Critical Infrastructure (Water utilities, Telecommunications), Government (Regional bodies), Education (Universities).
* **Geography:** Primarily Portuguese- and Spanish-speaking countries across Europe, Africa, and Latin America. Historically targeted the US, Brazil, India, Russia, Taiwan, and Japan.
* **Victims:** Includes a water utility, a telecommunications provider, a regional government body, and a university.
## Tools & Infrastructure
* **Malware:** Warlock Ransomware.
* **Drivers:** K7RKScan (vulnerable signed driver - CVE-2025-1055).
* **Infrastructure:**
* litter[.]catbox[.]moe
* xn8xyt-drop[.]s3[.]wasabisys[.]com
* **Software Abuse:** Microsoft SharePoint, Visual Studio Code (tunneling).
## Implications
Longlegs represents a sophisticated threat to critical infrastructure, combining high-speed ransomware deployment with advanced evasion techniques. Their ability to exploit complex enterprise software (SharePoint) and use legitimate administrative features (SYSVOL replication and VS Code tunnels) indicates a high level of technical proficiency. The transition from espionage-aligned clusters (CamoFei/ChamelGang) to ransomware (Warlock) suggests a diversified or financially motivated shift in their operational goals.
## Mitigations
* **SharePoint Hardening:** Prioritize patching for SharePoint vulnerabilities, specifically CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771.
* **Driver Blocklisting:** Implement Microsoft’s recommended vulnerable driver blocklist to prevent BYOVD attacks using K7RKScan.
* **Monitor SYSVOL:** Audit and alert on the creation of executable files within the SYSVOL share, as this is an atypical location for non-policy related files.
* **Restrict Tunnels:** Monitor or disable Visual Studio Code tunneling features on production servers and workstations not used for development.
* **Machine Key Protection:** Rotate ASP.NET machine keys if a SharePoint compromise is suspected to invalidate forged payloads.