Skip to content

Image: securityaffairs.com · rights & removal

Executive Summary

The Longlegs group, associated with Warlock ransomware, continues to exploit vulnerabilities in SharePoint as an initial access vector, utilizing the ToolShell vulnerability. This group has demonstrated a sustained pattern of targeting organizations across diverse geographic locations, including Portuguese- and Spanish-speaking countries in Europe, Africa, and Latin America, as well as nations like the US, Brazil, India, Russia, Taiwan, and Japan. The attackers use SharePoint flaws to establish initial access, subsequently deploying webshells, using DLL sideloading from legitimate hosting services for payload delivery, and employing vulnerable drivers to disable security software before deploying ransomware. Attacks have progressed methodically, involving reconnaissance, staging of payloads across multiple hosts via domain account manipulation, and the final deployment of Warlock ransomware, often leveraging domain replication traffic to distribute the malware across a network.

Facts Only

* Warlock ransomware exploited SharePoint zero-days collectively named ToolShell in mid-2025.
* The group behind Warlock is tracked by Symantec as Longlegs, also known as Storm-2603.
* Longlegs is traced back to China-nexus clusters: CL-CRI-1040, CamoFei, and ChamelGang.
* In the past two months, Longlegs hit at least four organizations: a water utility, a telecom provider, a regional government body, and a university in Portuguese or Spanish speaking countries across Europe, Africa, and Latin America.
* The group has targeted organizations in the US, Brazil, India, Russia, Taiwan, and Japan.
* The initial access method involves placing a webshell in the LAYOUTS directory to steal ASP.NET machine keys for payload creation.
* DLL sideloading is used to run additional payloads from services like catbox.moe and wasabisys.com.
* A signed but vulnerable driver called K7RKScan is used to disable security software, a "bring your own vulnerable driver" technique.
* Visual Studio Code’s tunneling feature was installed as a service for remote access.
* One intrusion against a critical infrastructure operator began on July 22, 2026, with the webshell landing on a SharePoint server.
* Attackers deployed a tool to disable security software on at least 40 hosts within two hours in one instance and Warlock ransomware on at least 33 hosts by staging it in the domain’s SYSVOL share.

Full Take

The persistence of ToolShell exploitation as an initial access vector, even over a year after the initial exposure, highlights a critical gap between vulnerability disclosure and enterprise remediation. The mechanism employed—leveraging shared application server structures like SharePoint to pivot to kernel-level or application-level execution via webshells and sideloading—suggests that defensive measures focusing solely on perimeter defense or simple patch management are insufficient against complex, multi-stage intrusions. The shift in focus toward geographically diverse targets might indicate an opportunistic scanning strategy rather than a single, deeply entrenched objective, where the accessibility of unpatched SharePoint instances serves as a low-friction entry point for widely distributed threat actors. Furthermore, the use of legitimate hosting services and established developer tools like VS Code tunneling indicates a sophisticated operational security practice designed to mask malicious activity within expected system noise, complicating attribution and detection. The fact that attackers pivot from initial access (SharePoint) to system disabling (K7RKScan), lateral movement (domain account creation), and final deployment via domain replication traffic demonstrates an understanding of internal Windows infrastructure mechanics, moving beyond simple file exfiltration into deep system control. This complexity demands a systemic shift in defense strategy, prioritizing continuous, automated configuration auditing over periodic patching cycles, especially for shared enterprise platforms.
Bridge Questions: If organizations assume that exploitation of known vulnerabilities like ToolShell is inevitable given the existence of public advisories, what internal controls must be established to fundamentally change the risk calculation associated with these entry points? How should defensive frameworks adapt to counter an adversary who leverages trusted application logic and legitimate development tools for privilege escalation and persistence? What responsibility do software vendors and infrastructure providers bear when vulnerabilities in foundational enterprise platforms create systemic risks across critical sectors?

From the original · Security Affairs (Pierluigi Paganini)

Warlock ransomware made headlines back in mid-2025 for exploiting a chain of SharePoint zero-days collectively dubbed ToolShell. More than a year later, the same group is still using that door, and it’s still getting in.
Read the full story at securityaffairs.com

Sentinel — Human

Confidence

The text reads like a synthesized journalistic report drawing directly from forensic findings, exhibiting structure and specificity consistent with human analysis of technical incident data.

Signals Detected
low severity: Varied sentence length and use of specific technical terminology without mechanical monotony.
low severity: Maintains a narrative flow linking historical context (Warlock, ToolShell) to current threat persistence and specific technical steps.
low severity: Specific details regarding attack timelines (July 22, July 28, July 31) and specific file/process names (dfsrs.exe) suggest deep source material.
low severity: The text synthesizes a complex chain of events from a reported source (Symantec) into an accessible narrative, which is characteristic of journalistic summary rather than raw LLM output.
Human Indicators
Use of specific attribution to a named report ('Symantec's report') and direct quotation from the source material lend credibility.
The flow transitions naturally between high-level threat assessment and granular technical execution details.
Warlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical Infrastructure | Huntaegis