Warlock Ransomware Attackers Hit Water and Telecom Operators via SharePoint ToolShell Exploitation (Longlegs / Storm-2603)
Warlock Ransomware Attackers Hit Water and Telecom Operators (TL-2026-2833), also tracked as Warlock ransomware campaign, is a critical-severity ransomware operation, first published 2026-10-01. It is attributed to Longlegs (China) with medium confidence, affects Microsoft SharePoint Server (on-premises), references 5 CVEs (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770), maps to 14 MITRE ATT&CK techniques (T1021.002, T1059.001, T1059.003), and is covered by 9 detection rules and 28 indicators of compromise.
Key facts for TL-2026-2833
- Threat ID
- TL-2026-2833
- Also known as
- Warlock ransomware campaign, ToolShell exploitation
- Severity
- CRITICAL
- Status
- ACTIVE
- Category
- RANSOMWARE
- First published
- 2026-10-01
- Last reviewed
- 2026-10-01
- Attribution
- Longlegs
- Attribution confidence
- MEDIUM
- Nation-state nexus
- China
- Motivation
- FINANCIAL
- Target sectors
- water, telecoms, government administration, education
- Target regions
- Europe, Africa, Latin America
- Detection rules
- 9
- Indicators of compromise
- 28
Malware and tooling in Warlock Ransomware Attackers Hit Water and Telecom Operators
Malware and tooling: Storm, WarLock, NetExec
China-nexus actor Longlegs (aka Storm-2603) is exploiting Microsoft SharePoint ToolShell vulnerabilities (CVE-2025-49704/49706/53770/53771) to deploy Warlock ransomware against water utilities, telecom providers, a regional government body and a university in Portuguese- and Spanish-speaking countries across Europe, Africa and Latin America. In one July 2026 intrusion Warlock reached 33+ hosts via SYSVOL replication after an AV/EDR killer using the vulnerable K7RKScan driver was run.
How Warlock Ransomware Attackers Hit Water and Telecom Operators works
Symantec's Threat Hunter Team (published 2026-10-01) reports at least four organizations hit over roughly two months: a water utility, a telecommunications provider, a regional government body and a university, all in Portuguese- and Spanish-speaking countries across Europe, Africa and Latin America. Earlier Warlock activity spanned the US, Brazil, India, Russia, Taiwan and Japan. Symantec attributes the activity to Longlegs (aka Storm-2603), a China-nexus actor, and links it to the CL-CRI-1040, CamoFei and ChamelGang clusters. Warlock emerged in June 2025 and exploited the ToolShell SharePoint zero-days weeks later.
Initial access is the ToolShell chain against on-premises SharePoint (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, CVE-2025-53771), using forged, machine-key-signed __VIEWSTATE payloads to execute code in the SharePoint application pool. In the detailed intrusion, a PowerShell command wrote the webshell layout2sp.aspx into the SharePoint 14 hive template\layouts directory on 2026-07-22. The actor then ran reconnaissance (net user /domain, whoami, nltest /domain_trusts), cleaned up staging artifacts, issued an outbound request to a Burp Collaborator (oastify.com) canary, re-tested the webshell, and loaded System.Workflow.ComponentModel via reflection in PowerShell as part of the exploit chain. ASP.NET machine keys were harvested to forge payloads.
On 2026-07-29 the domain account SPSEPRDSetup was added to the local Administrators group and Visual Studio Code Insiders was installed as a tunnel service (code-insiders.exe tunnel service install --accept-server-license-terms) for covert remote access that blends with developer traffic. Payload MSIs were pulled with msiexec /q /i from file-sharing/cloud storage (litter.catbox.moe, s3.wasabisys.com/fortifs, xn8xyt-drop.s3.wasabisys.com). Persistence and execution used DLL sideloading pairs (ssvagent.exe + gsdll64.dll.tmp, logger.exe + doexeloc.dll.tmp, doexe.exe + doexeloc.dll). NetExec (nxc.exe) was used for AD enumeration, credential spraying and remote execution.
Defense evasion used an AV/EDR killer (a.exe) that abuses the vulnerable K7RKScan kernel driver (CVE-2025-1055) in a BYOVD technique, staged from an SMB share and run via net use / copy / start /B. On 2026-07-31 Warlock (run.exe / rune.exe) was staged in the domain SYSVOL scripts share and copied to C:\Users\Public and started on hosts via cmd, with dfsrs.exe confirming SYSVOL replication delivery. In about two hours the killer ran on 40 hosts and Warlock on 33 hosts. No CVSS score is stated in the source.
MITRE ATT&CK techniques used in TL-2026-2833
Lateral Movement
T1021.002 Remote Services: SMB/Windows Admin Shares
Execution
T1059.001 Command and Scripting Interpreter: PowerShell; T1059.003 Command and Scripting Interpreter: Windows Command Shell
Discovery
T1087.002 Account Discovery: Domain Account; T1482 Domain Trust Discovery
Persistence
T1098.007 Account Manipulation: Additional Local or Domain Groups; T1505.003 Server Software Component: Web Shell
Credential Access
T1110.003 Brute Force: Password Spraying
Initial Access
T1190 Exploit Public-Facing Application
Stealth
T1218.007 System Binary Proxy Execution: Msiexec; T1620 Reflective Code Loading
Command and Control
T1219.001 Remote Access Tools: IDE Tunneling
stealth
Defense Impairment
Affected products and versions in Warlock Ransomware Attackers Hit Water and Telecom Operators
- Microsoft — SharePoint Server (on-premises)
Vulnerable versions: Unpatched on-premises SharePoint exposed to ToolShell
Fixed in: Versions with the security updates for CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, CVE-2025-53771 - K7 Computing — K7RKScan driver (abused for BYOVD, CVE-2025-1055)
Vulnerable versions: Vulnerable K7RKScan driver builds
Remediation for Warlock Ransomware Attackers Hit Water and Telecom Operators
Patches
- Apply Microsoft SharePoint Server security updates for CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, CVE-2025-53771
Immediate actions
- Patch on-premises SharePoint Server against CVE-2025-49704, CVE-2025-49706, CVE-2025-53770 and CVE-2025-53771
- Hunt for layout2sp.aspx and other unexpected files in the SharePoint 14\template\layouts directory
- Rotate ASP.NET machine keys on SharePoint servers
- Alert on msiexec /q /i installs from remote URLs, including catbox.moe and wasabisys.com
- Alert on code-insiders.exe tunnel service install and on SYSVOL scripts containing executables
Workarounds
- Block catbox.moe and wasabisys.com egress where not business-required
- Restrict SharePoint exposure to the internet
Longer-term hardening
- Block or restrict VS Code tunnel features in production environments
- Monitor LOLBin recon (net user /domain, whoami, nltest /domain_trusts) and unauthorized additions to local admin groups
- Audit SYSVOL/DFSR replication and Group Policy execution
- Enable vulnerable-driver blocklisting (HVCI / Microsoft driver blocklist) to blunt BYOVD
- Apply the additional SharePoint hardening guidance in the July 2026 CISA advisory cited by Symantec
CVEs associated with Warlock Ransomware Attackers Hit Water and Telecom Operators
CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, CVE-2025-53771, CVE-2025-1055
Timeline of Warlock Ransomware Attackers Hit Water and Telecom Operators
- Warlock ransomware first emerges (June 2025 per Symantec); ToolShell SharePoint zero-days exploited weeks later
- Webshell layout2sp.aspx written to a victim SharePoint server via PowerShell
- Reconnaissance commands (net user /domain, whoami, nltest /domain_trusts) executed and staging artifacts cleaned up
- Outbound web request to a Burp Collaborator (oastify.com) domain from the compromised server
- Webshell re-tested and ToolShell exploitation chain activity begins
- Domain account SPSEPRDSetup added to local administrators; VS Code Insiders tunnel service installed
- DLL sideloading persistence activity and deployment of the AV/EDR killer (K7RKScan BYOVD) begin, continuing to July 31
- Warlock deployed via SYSVOL replication; AV/EDR killer on 40 hosts and Warlock on 33 hosts in about two hours
- Symantec Threat Hunter Team publishes analysis of Warlock attacks on water and telecom operators
Sources cited for Warlock Ransomware Attackers Hit Water and Telecom Operators
- Warlock Ransomware Attackers Hit Water and Telecom Operators (Symantec Threat Hunter Team)
- MITRE ATT&CK Campaign C0058: SharePoint ToolShell Exploitation
- Warlock Group: The Rise of GOLD SALEM (Storm-2603) in 2025's Ransomware Landscape (Brandefense)
- Storm-2603 spotted deploying ransomware on exploited SharePoint servers (Help Net Security)
- SharePoint Zero-Days Exploited to Unleash Warlock Ransomware (BankInfoSecurity)
- SharePoint-ageddon attacks riddled with free Warlock ransomware (TechRadar)
More in ransomware
- Operation KillSwitch: International Takedown of the KillSec Data-Theft Extortion Ransomware Group
- Microsoft Tracks Storm-2570 Ransomware Affiliate Behind Qilin, DragonForce, Anubis, and BERT Deployments
- BlueLocker Ransomware Resurfaces After Three-Year Dormancy, Breaches Pakistan Petroleum Limited
- Storm-3168 (JADEPUFFER): Agentic-Driven Destructive Cloud Attacks Against Azure via Compromised Service Principals
- Vexy Ransomware Claims Data-Extortion Attack on Majani Insurance Brokers (Kenya)
Detection coverage for TL-2026-2833
As of 2026-10-01, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2833 across Splunk SPL, Microsoft KQL and Sigma, covering 28 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-2833
2 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.