Skip to content

Warlock ransomware hits critical infrastructure via SharePoint

Symantec says the Warlock operator, tracked as Longlegs/Storm-2603, hit a water utility, a telecom, a regional government and a university using ToolShell SharePoint exploits.

Published 2 min read

Symantec's Threat Hunter Team reports that the operator behind Warlock ransomware has hit at least four critical-infrastructure and public-sector organizations in Portuguese- and Spanish-speaking countries over the past two months, still entering through Microsoft SharePoint. The primary writeup is Symantec's October 2 report.

Who and what

Symantec attributes the activity to a group it tracks as Longlegs (aka Storm-2603), a China-nexus actor it links to prior clusters CL-CRI-1040, CamoFei, and ChamelGang. Attribution is Symantec's; no indictment or sanction makes it official. Named victims are given by sector, not name: a water utility, a telecommunications provider, a regional government body, and a university, spanning Europe, Africa, and Latin America.

How they get in

The entry point remains the ToolShell SharePoint chain disclosed in 2025:

Post-exploitation, Symantec observed web-shell deployment, ASP.NET machine-key harvesting for forged __VIEWSTATE code execution, DLL sideloading via legitimate binaries, abuse of the CVE-2025-1055 K7RKScan vulnerable driver to disable security tooling, Visual Studio Code tunnels for covert remote access, and payload staging in SYSVOL for domain-wide ransomware distribution. Living-off-the-land tooling — net, nltest, NetExec — fills the gaps.

Exploitation status

Confirmed in the wild by Symantec, which published indicators. If your SharePoint servers were internet-reachable and unpatched against ToolShell at any point since July 2025, assume probing.

Symantec's published IOCs, verbatim:

File hashes (SHA-256):
116ca4e88a1bcebb6c0da7fb431c8eca7b8ef3f9767194820c56091972ccac2c
155fb1cbdaea12c83ba92d18c88cf38bbc42bb684f913ca0bc26fcf115426a55
1edb2c0b537cd95bbd5fc16321b4c38a6adf325ccc7b588ad6acc980b0463b60
206f27ae820783b7755bca89f83a0fe096dbb510018dd65b63fc80bd20c03261
27b7591cf9e1283010ca98fa5dbe970a73fee0d8cde277639924c144718db7c0
37f94fe1b4a106f02b6f74a69cbc05e69c17406f688beef4c9a045ffcbd2e65e
6d07f1232dc59b84038fd0b2e75fdd3d5b825882bb0dba9e6724b7b0823fa3ad
73c5268256c9da5488cd9e2b79013060ac321c7e54129344dc7b51e268af36ea
8b58f7811a2a2f2a5024220490473774f02759dd2dd904b5b9fabfbaae37125f
8ce8d8270ee9de02644530b8dd7fa78973b4a3b80f121e2c5f45ae68cce196f9
9ceb01f8bf7d6dba2ae07f5bd6070de3ec67b5eb01f969b0ba85e74564fb83a7
aaff04d84ef85353966aa4af186ff1254b72c068f33f802417b29dc23fb9f192
ae9f7fce57c7b928e659dccf0e00fa79cd9cd61a106f18d4e03f92dc3a03c295
c46825fcc0d1bf7a8b192facb176d6bf916c9dccfd6fa994be691e3b0e585f4e
e14240bac8277b0f6dd4d29ab5da20d246bcccae647e5fe8d19cdae7fe471b20
e3204b05e2f3a29bb6e6fcc21dda77d7cd31dfa755c21da0aa8661b5619ee0a1
eea631b5f7125239db0811e4682c2316ead69f9822e02d94fb5d8bf0d2faebed
f7269f80f81e99d06a590d7ab374e12fdf7e5f55a02c2a46c342d670f8519fdf
fb3846c9ac53d1b841ada3a6b1091153fea41a169cb44fe0084097d1f4d45984

Network:
litter[.]catbox[.]moe
xn8xyt-drop[.]s3[.]wasabisys[.]com

Action checklist

  1. Patch SharePoint Server against the full ToolShell set if you somehow haven't — and rotate ASP.NET machine keys, because a compromise before rotation leaves forged-token access that a patch alone doesn't close.
  2. Hunt for the hashes and the two network indicators above across SharePoint hosts and reachable segments.
  3. Alert on VS Code tunnel processes and outbound *.devtunnels.ms traffic from servers that have no business running them.
  4. Check for the K7RKScan driver (CVE-2025-1055) being loaded on SharePoint and adjacent Windows hosts; block it via vulnerable-driver lists.
  5. Review SYSVOL for unexpected binaries — domain-wide staging lives there.

Context

This is the same ToolShell chain still producing incidents more than a year after disclosure, now carrying ransomware into critical infrastructure rather than espionage payloads. The machine-key-theft step is why "we patched" is not "we're clean": once keys are stolen, the door stays open until they're rotated — a detail that keeps turning unpatched-SharePoint stories into months-later ransomware stories.

Related stories