Warlock Ransomware Attackers Hit Water and Telecom Operators via SharePoint ToolShell Exploitation (Longlegs / Storm-2603)

Warlock Ransomware Attackers Hit Water and Telecom Operators (TL-2026-2833), also tracked as Warlock ransomware campaign, is a critical-severity ransomware operation, first published 2026-10-01. It is attributed to Longlegs (China) with medium confidence, affects Microsoft SharePoint Server (on-premises), references 5 CVEs (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770), maps to 14 MITRE ATT&CK techniques (T1021.002, T1059.001, T1059.003), and is covered by 9 detection rules and 28 indicators of compromise.

Key facts for TL-2026-2833

Threat ID
TL-2026-2833
Also known as
Warlock ransomware campaign, ToolShell exploitation
Severity
CRITICAL
Status
ACTIVE
Category
RANSOMWARE
First published
2026-10-01
Last reviewed
2026-10-01
Attribution
Longlegs
Attribution confidence
MEDIUM
Nation-state nexus
China
Motivation
FINANCIAL
Target sectors
water, telecoms, government administration, education
Target regions
Europe, Africa, Latin America
Detection rules
9
Indicators of compromise
28

Malware and tooling in Warlock Ransomware Attackers Hit Water and Telecom Operators

Malware and tooling: Storm, WarLock, NetExec

China-nexus actor Longlegs (aka Storm-2603) is exploiting Microsoft SharePoint ToolShell vulnerabilities (CVE-2025-49704/49706/53770/53771) to deploy Warlock ransomware against water utilities, telecom providers, a regional government body and a university in Portuguese- and Spanish-speaking countries across Europe, Africa and Latin America. In one July 2026 intrusion Warlock reached 33+ hosts via SYSVOL replication after an AV/EDR killer using the vulnerable K7RKScan driver was run.

How Warlock Ransomware Attackers Hit Water and Telecom Operators works

Symantec's Threat Hunter Team (published 2026-10-01) reports at least four organizations hit over roughly two months: a water utility, a telecommunications provider, a regional government body and a university, all in Portuguese- and Spanish-speaking countries across Europe, Africa and Latin America. Earlier Warlock activity spanned the US, Brazil, India, Russia, Taiwan and Japan. Symantec attributes the activity to Longlegs (aka Storm-2603), a China-nexus actor, and links it to the CL-CRI-1040, CamoFei and ChamelGang clusters. Warlock emerged in June 2025 and exploited the ToolShell SharePoint zero-days weeks later.

Initial access is the ToolShell chain against on-premises SharePoint (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, CVE-2025-53771), using forged, machine-key-signed __VIEWSTATE payloads to execute code in the SharePoint application pool. In the detailed intrusion, a PowerShell command wrote the webshell layout2sp.aspx into the SharePoint 14 hive template\layouts directory on 2026-07-22. The actor then ran reconnaissance (net user /domain, whoami, nltest /domain_trusts), cleaned up staging artifacts, issued an outbound request to a Burp Collaborator (oastify.com) canary, re-tested the webshell, and loaded System.Workflow.ComponentModel via reflection in PowerShell as part of the exploit chain. ASP.NET machine keys were harvested to forge payloads.

On 2026-07-29 the domain account SPSEPRDSetup was added to the local Administrators group and Visual Studio Code Insiders was installed as a tunnel service (code-insiders.exe tunnel service install --accept-server-license-terms) for covert remote access that blends with developer traffic. Payload MSIs were pulled with msiexec /q /i from file-sharing/cloud storage (litter.catbox.moe, s3.wasabisys.com/fortifs, xn8xyt-drop.s3.wasabisys.com). Persistence and execution used DLL sideloading pairs (ssvagent.exe + gsdll64.dll.tmp, logger.exe + doexeloc.dll.tmp, doexe.exe + doexeloc.dll). NetExec (nxc.exe) was used for AD enumeration, credential spraying and remote execution.

Defense evasion used an AV/EDR killer (a.exe) that abuses the vulnerable K7RKScan kernel driver (CVE-2025-1055) in a BYOVD technique, staged from an SMB share and run via net use / copy / start /B. On 2026-07-31 Warlock (run.exe / rune.exe) was staged in the domain SYSVOL scripts share and copied to C:\Users\Public and started on hosts via cmd, with dfsrs.exe confirming SYSVOL replication delivery. In about two hours the killer ran on 40 hosts and Warlock on 33 hosts. No CVSS score is stated in the source.

MITRE ATT&CK techniques used in TL-2026-2833

Lateral Movement

T1021.002 Remote Services: SMB/Windows Admin Shares

Execution

T1059.001 Command and Scripting Interpreter: PowerShell; T1059.003 Command and Scripting Interpreter: Windows Command Shell

Discovery

T1087.002 Account Discovery: Domain Account; T1482 Domain Trust Discovery

Persistence

T1098.007 Account Manipulation: Additional Local or Domain Groups; T1505.003 Server Software Component: Web Shell

Credential Access

T1110.003 Brute Force: Password Spraying

Initial Access

T1190 Exploit Public-Facing Application

Stealth

T1218.007 System Binary Proxy Execution: Msiexec; T1620 Reflective Code Loading

Command and Control

T1219.001 Remote Access Tools: IDE Tunneling

stealth

T1574.001 DLL

Defense Impairment

T1685 Disable or Modify Tools

Affected products and versions in Warlock Ransomware Attackers Hit Water and Telecom Operators

  • Microsoft — SharePoint Server (on-premises)
    Vulnerable versions: Unpatched on-premises SharePoint exposed to ToolShell
    Fixed in: Versions with the security updates for CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, CVE-2025-53771
  • K7 Computing — K7RKScan driver (abused for BYOVD, CVE-2025-1055)
    Vulnerable versions: Vulnerable K7RKScan driver builds

Remediation for Warlock Ransomware Attackers Hit Water and Telecom Operators

Patches

  • Apply Microsoft SharePoint Server security updates for CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, CVE-2025-53771

Immediate actions

  • Patch on-premises SharePoint Server against CVE-2025-49704, CVE-2025-49706, CVE-2025-53770 and CVE-2025-53771
  • Hunt for layout2sp.aspx and other unexpected files in the SharePoint 14\template\layouts directory
  • Rotate ASP.NET machine keys on SharePoint servers
  • Alert on msiexec /q /i installs from remote URLs, including catbox.moe and wasabisys.com
  • Alert on code-insiders.exe tunnel service install and on SYSVOL scripts containing executables

Workarounds

  • Block catbox.moe and wasabisys.com egress where not business-required
  • Restrict SharePoint exposure to the internet

Longer-term hardening

  • Block or restrict VS Code tunnel features in production environments
  • Monitor LOLBin recon (net user /domain, whoami, nltest /domain_trusts) and unauthorized additions to local admin groups
  • Audit SYSVOL/DFSR replication and Group Policy execution
  • Enable vulnerable-driver blocklisting (HVCI / Microsoft driver blocklist) to blunt BYOVD
  • Apply the additional SharePoint hardening guidance in the July 2026 CISA advisory cited by Symantec

CVEs associated with Warlock Ransomware Attackers Hit Water and Telecom Operators

CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, CVE-2025-53771, CVE-2025-1055

Timeline of Warlock Ransomware Attackers Hit Water and Telecom Operators

  • Warlock ransomware first emerges (June 2025 per Symantec); ToolShell SharePoint zero-days exploited weeks later
  • Webshell layout2sp.aspx written to a victim SharePoint server via PowerShell
  • Reconnaissance commands (net user /domain, whoami, nltest /domain_trusts) executed and staging artifacts cleaned up
  • Outbound web request to a Burp Collaborator (oastify.com) domain from the compromised server
  • Webshell re-tested and ToolShell exploitation chain activity begins
  • Domain account SPSEPRDSetup added to local administrators; VS Code Insiders tunnel service installed
  • DLL sideloading persistence activity and deployment of the AV/EDR killer (K7RKScan BYOVD) begin, continuing to July 31
  • Warlock deployed via SYSVOL replication; AV/EDR killer on 40 hosts and Warlock on 33 hosts in about two hours
  • Symantec Threat Hunter Team publishes analysis of Warlock attacks on water and telecom operators

Sources cited for Warlock Ransomware Attackers Hit Water and Telecom Operators

More in ransomware

Detection coverage for TL-2026-2833

As of 2026-10-01, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2833 across Splunk SPL, Microsoft KQL and Sigma, covering 28 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Community OSINT corroboration for TL-2026-2833

2 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats