Symantec’s threat hunters report that the China-nexus group behind Warlock ransomware, tracked as Storm-2603 (Microsoft) and Longlegs (Symantec), is still getting in through Microsoft SharePoint. Over roughly the past two months the group has hit at least four organizations in Portuguese- and Spanish-speaking countries across Europe, Africa and Latin America. The victims include a water utility, a telecommunications provider, a regional government body and a university.
What happened
Warlock first appeared in June 2025. Weeks later, its operators were caught exploiting the SharePoint “ToolShell” zero-days (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, CVE-2025-53771). The new intrusions show the group still treats on-premises SharePoint as its preferred door. Symantec describes the initial access as suspected SharePoint exploitation. The specific CVE used in each case has not been confirmed publicly.
The reporting does not tie these intrusions to a single new SharePoint bug. The pattern is the same as before: exploit an exposed SharePoint server, steal ASP.NET machine keys, and use them to regain access after a patch. Our earlier coverage of recent SharePoint flaws, including CVE-2026-50522 machine key theft, applies to the same attack surface.
Post-exploitation tradecraft
The notable part of this campaign is what happens after the foothold.
- AV/EDR killers via BYOVD. The operators load the signed but vulnerable K7RKScan driver (tracked as CVE-2025-1055) and use it to terminate privileged security processes from kernel space. Symantec saw the killer tooling on at least 40 hosts in one environment.
- DLL sideloading. Loaders are run through legitimate signed binaries to blend in with normal process activity.
- VS Code tunnels for covert access. The attackers install the Microsoft-signed
code-insiders.exeas a service and use Visual Studio Code’s tunnel feature. The resulting traffic goes to Microsoft infrastructure, which defenders often associate with developers or admins. - Domain-wide deployment from SYSVOL. Warlock binaries are staged in SYSVOL. Domain controller replication then spreads them, and host-side copy and execute steps launch them. Warlock was present on at least 33 hosts in the broadest intrusion.
Reported infrastructure includes litter[.]catbox[.]moe and xn8xyt-drop[.]s3[.]wasabisys[.]com. Operators were also seen making oastify.com lookups from servers, which is a common out-of-band callback used to confirm that an exploit worked.
Impact
Any organization running internet-facing, on-premises SharePoint is in scope. Water and telecom victims put this in the critical-infrastructure bucket, where the cost of an outage is high and the pressure to pay is greater. Because deployment rides on SYSVOL and domain replication, a compromise that reaches a domain controller can become domain-wide encryption quickly.
Mitigation
- Patch SharePoint Server to the latest cumulative update, including the fixes for the ToolShell chain. Keep SharePoint off the public internet where you can, or front it with an authenticating reverse proxy.
- Rotate ASP.NET machine keys (validation and decryption keys) after any suspected compromise. A patch alone does not evict an attacker who already holds the keys.
- Block vulnerable drivers. Enable the Microsoft vulnerable driver blocklist and HVCI, and add K7RKScan to your block rules.
- Hunt for VS Code tunnels. Alert on
code-insiders.exeorcode.exerunning as a service or withtunnelarguments on servers, and on unexpectedmsiexecdownloads. - Watch SYSVOL. Alert on new executables or scripts written to SYSVOL or NETLOGON, and restrict write access to it.
- Egress filtering. Block or alert on
oastify.comlookups from servers and on connections to the file-drop domains above.