New data from Symantec observed that the China-nexus group behind Warlock ransomware, tracked as Longlegs or Storm-2603, has continued exploiting vulnerabilities in on-premises Microsoft SharePoint Server to gain initial access to victim environments. Over the past two months, the group targeted at least four organizations in Portuguese- and Spanish-speaking countries across Europe, Africa and Latin America. The victims included a water utility, a telecommunications provider, a regional government body and a university, highlighting the group’s activity across organizations operating critical or publicly important services.
“Warlock emerged in June 2025 and hit the headlines weeks later, when attackers deploying it were found exploiting zero-day vulnerabilities in Microsoft SharePoint Server, dubbed ‘ToolShell’ (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771),” Symantec Threat Hunter Team wrote in a Thursday blog post. “Those flaws likely remain in the group’s arsenal, alongside newer SharePoint flaws, which the U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned about in an advisory published in July 2026.”
The researchers wrote that in one intrusion against a critical infrastructure operator, the attackers pushed a tool designed to disable security software to at least 40 hosts within about two hours, then deployed Warlock on at least 33 hosts by staging it in the domain’s SYSVOL share, where ordinary domain replication delivered it to machines.
In an intrusion involving a critical infrastructure operator, Longlegs used a tool to disable security software on at least 40 hosts within about two hours before deploying Warlock ransomware on at least 33 hosts, according to Symantec. The attackers staged the ransomware in the domain’s SYSVOL share, enabling normal domain replication mechanisms to distribute the payload across machines. The group also used legitimate or built-in tools, DLL sideloading and Visual Studio Code’s tunneling capability for reconnaissance, execution and remote access, techniques that can make malicious activity harder to distinguish from legitimate administrative operations.
Symantec said the activity demonstrates how attackers can combine exploitation of internet-facing enterprise software with techniques designed to move through and disrupt large Windows environments. The group used compromised credentials and administrative access to conduct reconnaissance and execute commands across victim networks before deploying the ransomware. The attacks also involved efforts to impair security controls, allowing the threat actors to move from initial access toward broader network compromise and ransomware deployment.
The researchers identified that Longlegs typically gains initial access by exploiting multiple vulnerabilities in on-premises Microsoft SharePoint Server deployments. “Once inside, the group drops a webshell into the SharePoint LAYOUTS directory for multiple SharePoint versions at once, ensuring the webshell will function regardless of which version is actually installed. The webshell’s function is to harvest the SharePoint farm’s ASP.NET machine keys, which the attackers then use to forge a validly signed payload that achieves remote code execution inside the SharePoint application pool.”
“Longlegs makes heavy use of living-off-the-land tooling to carry out reconnaissance and execute commands on compromised hosts,” Symantec reported. “The group has also been observed abusing Visual Studio Code’s built-in tunnel feature, installing the code-insiders.exe binary as a service to establish covert remote network access that blends into traffic that typically originates from developer or administrator workstations.”
Symantec observed that to deploy ransomware at scale, Longlegs stages its payloads inside the compromised domain’s SYSVOL share, a location that is automatically replicated to every domain controller and readable domain-wide. This lets the group push the ransomware out for execution across many machines on a victim’s network at once, rather than one host at a time.
“Longlegs’ continued activity, more than a year after Warlock ransomware first came to prominence, shows that exploitation of ToolShell and other related SharePoint vulnerabilities remains a viable initial access route for attackers SharePoint deployments that have not been patched or otherwise mitigated,” the researchers mentioned. “The apparent recent focus on Portuguese- and Spanish-speaking countries suggests either an opportunistic targeting pattern driven by exposed, vulnerable SharePoint servers, or a more deliberate tasking. The inclusion of critical infrastructure operators among the victims is a reminder of the potential real-world consequences of ransomware attacks that succeed against essential services.”


