Full Report
New data from Symantec observed that the China-nexus group behind Warlock ransomware, tracked as Longlegs or Storm-2603, has continued exploiting vulnerabilities in on-premises Microsoft SharePoint Server to gain initial access to victim environments. Over the past two months, the group targeted at least four organizations in Portuguese- and Spanish-speaking countries across Europe, Africa and Latin…
Analysis Summary
# Threat Actor: Warlock (Longlegs / Storm-2603)
## Attribution & Identity
- **Actor Name:** Warlock (refers to the ransomware family and the group operating it).
- **Aliases:** Longlegs (Symantec tracking), Storm-2603 (Microsoft tracking).
- **Attribution:** China-nexus group.
## Activity Summary
Warlock emerged in June 2025 and gained notoriety for exploiting zero-day vulnerabilities in Microsoft SharePoint Server. Recent activity (August–September 2026) shows the group continuing to exploit on-premises SharePoint flaws to target critical infrastructure and public service organizations across Europe, Africa, and Latin America. Notably, the group is capable of rapid lateral movement, once disabling security software on 40 hosts within two hours during a single intrusion.
## Tactics, Techniques & Procedures
- **Initial Access:** Exploitation of on-premises Microsoft SharePoint Server vulnerabilities.
- **Vulnerability Research:** Usage of "ToolShell" zero-day flaws and subsequent SharePoint vulnerabilities identified by CISA.
- **Defense Evasion:** Deployment of custom tools designed to disable security software.
- **Lateral Movement/Persistence:** Staging ransomware in the Active Directory domain’s **SYSVOL share**, leveraging ordinary domain replication to distribute the malware to multiple machines automatically.
- **Rapid Execution:** Capable of high-speed deployment (e.g., hitting 33+ hosts in approximately two hours).
- **MITRE ATT&CK IDs:**
- T1190 (Exploit Public-Facing Application)
- T1562.001 (Impair Defenses: Disable or Modify Tools)
- T1080 (Software Deployment Tools - SYSVOL replication)
## Targeting
- **Sectors:** Critical Infrastructure, Water Utilities, Telecommunications, Government (Regional), and Education (Universities).
- **Geography:** Portuguese- and Spanish-speaking countries across Europe, Africa, and Latin America.
- **Victims:** A water utility, a telecommunications provider, a regional government body, and a university (specific names not disclosed in the text).
## Tools & Infrastructure
- **Malware:** Warlock Ransomware.
- **Exploits:** "ToolShell" zero-day suite (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771) and newer SharePoint flaws reported in 2026.
- **Infrastructure:** Domain SYSVOL shares (internal infrastructure abuse).
## Implications
Warlock represents a significant threat to critical infrastructure due to its China-nexus attribution and its sophisticated use of zero-day exploits. Their shift toward ransomware suggests either a financially motivated pivot or a "ransomware-as-decoy" strategy for disruptive purposes. The group’s focus on Lusophone (Portuguese-speaking) and Hispanophone (Spanish-speaking) regions indicates a specific geopolitical or economic targeting priority. Their ability to weaponize standard Windows features like SYSVOL replication for rapid malware delivery shows a high level of operational maturity.
## Mitigations
- **Patch Management:** Prioritize immediate updates for on-premises Microsoft SharePoint Servers, specifically targeting CVEs related to the "ToolShell" vulnerability set and 2026 CISA advisories.
- **Monitor SYSVOL:** Implement auditing for the domain SYSVOL share to detect the staging of unauthorized executables or scripts.
- **Endpoint Protection:** Use EDR (Endpoint Detection and Response) tools to monitor for unauthorized attempts to disable security services or modify registry keys associated with antivirus software.
- **Network Segmentation:** Isolate SharePoint servers from the broader internal network to prevent lateral movement following initial exploitation.