The PolySwarm Blog

Analyze suspicious files and URLs, at scale, millions of times per day. Get real-time threat intel from a crowdsourced network of security experts and antivirus companies competing to protect you.

China Linked Warlock Ransomware Campaign Targets Critical Infrastructure

Oct 9, 2026, 11:44:14 AM / by The Hivemind

Threat Bulletin - CHINALINKEDWARLOCK2026Verticals Targeted: Water, Telecommunications, Government, Education
Regions Targeted: Europe, Africa, Latin America
Related Families: Warlock
Related Threat Actors: Longlegs

Executive Summary

A China-nexus threat actor tracked by Symantec as Longlegs is continuing to exploit vulnerabilities in on-premises Microsoft SharePoint Server to deploy Warlock ransomware, with recent victims including water and telecommunications operators, a regional government body, and a university. The group combines SharePoint exploitation with webshells, DLL sideloading, living-off-the-land techniques, vulnerable driver abuse, and Visual Studio Code tunneling before disabling security tools and deploying ransomware across compromised environments. In one critical infrastructure intrusion, the attackers deployed an AV/EDR-killing tool to at least 40 hosts within approximately two hours and subsequently delivered Warlock to at least 33 systems, using the victim's own SYSVOL replication infrastructure as part of the ransomware distribution process.


Key Takeaways

  • Longlegs continues to exploit vulnerabilities affecting on-premises Microsoft SharePoint Server, demonstrating that vulnerable or previously compromised SharePoint deployments remain a viable entry point.
  • Recent Longlegs activity affected at least four organizations in Portuguese- and Spanish-speaking countries across Europe, Africa, and Latin America, including a water utility and telecommunications provider.
  • The actor combines malicious tooling with legitimate administrative and development capabilities, including PowerShell, NetExec, Microsoft-signed Visual Studio Code binaries, cloud-hosting services, and Active Directory infrastructure.
  • Longlegs has abused signed but vulnerable drivers to disable endpoint security products prior to ransomware deployment.
  • In one critical infrastructure intrusion, the attackers staged Warlock inside the victim's SYSVOL infrastructure, allowing normal domain replication to participate in distributing the ransomware payloads.

What is Warlock Ransomware?

Warlock is a ransomware family that emerged in June 2025 and quickly gained attention after it was deployed in attacks exploiting vulnerabilities in on-premises Microsoft SharePoint Server. The ransomware is associated with the China-nexus threat actor Longlegs, also tracked as Storm-2603, which Symantec assesses is responsible for developing and deploying Warlock.

Warlock became particularly prominent during exploitation of the SharePoint vulnerabilities collectively associated with the ToolShell campaign. The original ToolShell exploit chain involved CVE-2025-49704 and CVE-2025-49706, with subsequent exploitation activity involving the related CVE-2025-53770 and CVE-2025-53771 vulnerabilities. These flaws provided attackers with a path from an exposed SharePoint server to remote code execution and further compromise of the underlying environment.

Warlock operations are notable not simply because of the ransomware payload itself, but because of the intrusion activity preceding encryption. Longlegs has combined SharePoint exploitation with webshell deployment, credential and Active Directory reconnaissance, DLL sideloading, living-off-the-land techniques, legitimate cloud-hosting services, vulnerable-driver abuse, and covert remote access. The group has also abused legitimate Microsoft Visual Studio Code tunneling functionality, allowing attacker-controlled remote access to blend with traffic associated with trusted software and infrastructure.

Recent activity shows that Warlock remains an active threat more than a year after its emergence. Over the past two months, Symantec observed Longlegs attacking at least four organizations in Portuguese- and Spanish-speaking countries across Europe, Africa, and Latin America. Victims included a water utility, telecommunications provider, regional government body, and university. Warlock activity has previously been observed against organizations in a broader range of countries, including the United States, Brazil, India, Russia, Taiwan, and Japan.

The group's continued use of SharePoint vulnerabilities is particularly significant for organizations still operating on-premises SharePoint infrastructure. Rather than treating ransomware as a standalone malware event, recent Warlock activity demonstrates an intrusion lifecycle in which exploitation of an internet-facing application can provide the initial foothold for broader Active Directory compromise, security-control disruption, lateral movement, and ultimately ransomware deployment across dozens of systems.

In one recent critical infrastructure intrusion documented by Symantec, this progression culminated in the attackers disabling endpoint protection across much of the environment and staging Warlock binaries inside the victim's SYSVOL share. Normal domain replication then helped distribute the ransomware across the network, with Warlock ultimately observed on at least 33 hosts.

The Attacks

Longlegs typically gains access by exploiting vulnerabilities affecting on-premises Microsoft SharePoint Server. Following compromise, the attackers deploy a webshell into SharePoint's LAYOUTS directory. Symantec observed the actor placing the webshell into directories corresponding to multiple SharePoint versions, allowing the same intrusion workflow to function regardless of the version installed. The webshell is then used to obtain ASP.NET machine keys from the SharePoint farm. These keys allow the attackers to construct validly signed payloads capable of achieving remote code execution within the SharePoint application pool.

In the critical infrastructure intrusion detailed by Symantec, exploitation of SharePoint vulnerabilities was assessed as the likely initial infection vector. The first observed malicious activity occurred on July 22, 2026, when a webshell was installed on a SharePoint server. This technique means patching alone may be insufficient once exploitation has already occurred.

Once established inside an environment, Longlegs employs a mixture of malicious tooling and legitimate system utilities. The group uses DLL sideloading to execute malicious code in memory and has retrieved follow-on payloads from legitimate cloud storage and file-sharing services, including Catbox and Wasabi. Using legitimate hosting infrastructure can make malicious downloads more difficult to distinguish from ordinary network activity when defenders rely primarily on domain reputation. Longlegs also uses a bring-your-own-vulnerable-driver, or BYOVD, technique to interfere with endpoint protection.

Symantec has observed the group abusing the signed but vulnerable K7RKScan driver, associated with CVE-2025-1055, to terminate protected security processes at the kernel level before ransomware deployment. The specific vulnerable driver used during the documented critical infrastructure intrusion was not identified. Symantec reported K7RKScan use in other recent Longlegs attacks, meaning its use should not be assumed for this particular intrusion. The technique nevertheless demonstrates the limitations of controls based solely on whether code carries a trusted signature.

Longlegs makes extensive use of legitimate utilities during reconnaissance and lateral movement. The activity allows the attackers to enumerate users and Active Directory relationships, execute commands, perform credential spraying, and expand access across the compromised domain. During the documented intrusion, msiexec.exe was used to retrieve MSI packages from public hosting infrastructure, including Catbox and Wasabi. One of the more notable techniques was abuse of Visual Studio Code's built-in tunneling capability. Longlegs installed the Microsoft-signed code-insiders.exe binary as a service and used its tunnel functionality to establish remote access. Because Visual Studio Code is legitimate software and the tunnel communicates through Microsoft infrastructure, the resulting activity can blend more easily with traffic associated with legitimate developers or administrators.

The critical infrastructure intrusion documented by Symantec demonstrates how rapidly a likely SharePoint compromise can develop into domain-wide ransomware deployment. The first observed malicious activity occurred on July 22, when a webshell was installed on a SharePoint server. Over the following days, the attackers conducted reconnaissance, established DLL-sideloading mechanisms, tested code execution, retrieved additional payloads, expanded administrative access, installed a VS Code tunnel, and used NetExec to operate across the Active Directory environment. The final phase began during the early hours of July 31. Longlegs distributed an AV/EDR-killing utility across the victim environment. Execution of the tool was recorded on at least 40 additional hosts within approximately two hours, indicating that the attackers were attempting to disable security controls across much of the environment. Warlock followed almost immediately.

Two ransomware binaries, run.exe and rune.exe, together with a ransom note named “how to restore your files.txt”, were recorded on at least 33 hosts. Critically, Longlegs staged the ransomware inside the victim domain's SYSVOL share. SYSVOL is replicated between domain controllers and is readable throughout an Active Directory domain. By placing the ransomware payload in this trusted administrative infrastructure, the attackers could leverage normal domain replication rather than independently delivering the ransomware to every endpoint.

Telemetry from three systems showed dfsrs.exe, the Distributed File System Replication service responsible for SYSVOL replication, as the parent responsible for delivering the Warlock binaries. This confirmed that normal SYSVOL replication propagated the malicious files. The technique effectively turned a core Active Directory capability into part of the ransomware deployment infrastructure.

Who is Longlegs?

Longlegs is a China-nexus threat actor also known as Storm-2603. Symantec assesses that Longlegs is responsible for developing and deploying Warlock ransomware and has connected the group to earlier activity clusters tracked as CL-CRI-1040, CamoFei, and ChamelGang. Related historical activity has included network intrusions, ransomware, and espionage operations.

Microsoft separately tracks Storm-2603 as a China-based threat actor and has observed the group exploiting vulnerabilities in on-premises Microsoft SharePoint environments to deploy Warlock ransomware. Microsoft has stated that it cannot confidently assess Storm-2603's objectives and has not definitively linked the actor to other known Chinese threat groups. This distinction is important because the available evidence supports describing Longlegs as a China-nexus actor, but does not establish that Warlock operations are Chinese state-sponsored activity.

Recent Longlegs operations demonstrate a combination of vulnerability exploitation, legitimate administrative tooling, living-off-the-land techniques, vulnerable-driver abuse, and ransomware deployment. The group's continued exploitation of SharePoint vulnerabilities more than a year after Warlock first emerged suggests that exposed or inadequately secured on-premises SharePoint infrastructure remains a viable entry point for its operations.

Analyst Commentary

The most significant aspect of this activity is not Warlock itself, but the attacker's ability to transition from exploitation of a vulnerable internet-facing application to large-scale ransomware deployment using trusted components already present within the victim environment. Longlegs repeatedly reduces its dependence on obviously malicious infrastructure. Legitimate cloud-hosting services deliver payloads, signed software establishes remote tunnels, standard Windows utilities perform reconnaissance, vulnerable but signed drivers disable security products, and Active Directory's own replication infrastructure distributes ransomware. Individually, several of these events can resemble legitimate administrative activity. Viewed as an attack chain, however, they show a clear progression toward domain-wide impact.

The SYSVOL technique is particularly important for defenders. Once an attacker reaches a position where trusted domain infrastructure can distribute malicious payloads, endpoint-by-endpoint containment becomes substantially more difficult. Detection, therefore, needs to occur earlier in the chain, particularly around exploitation, unusual SharePoint child processes, credential and domain enumeration, security-control tampering, and unexpected changes to privileged infrastructure. This activity also demonstrates the value of evaluating suspicious files and behaviors using multiple independent sources of threat intelligence rather than relying exclusively on reputation or a single detection engine. Attackers increasingly combine commodity tools, legitimate binaries, signed drivers, cloud services, and comparatively small amounts of purpose-built malware.

PolySwarm's multi-engine approach can help defenders assess suspicious artifacts across diverse detection technologies and identify disagreement or emerging detections that may be obscured when analysis depends on a single security vendor. For critical infrastructure operators, the operational implications are especially important. A compromise beginning on an enterprise-facing SharePoint server can ultimately affect systems across the broader Windows domain. Even where ransomware does not directly reach operational technology, disruption to identity services, telecommunications, administrative systems, engineering workstations, or other IT dependencies can affect an organization's ability to deliver essential services.

IOCs

PolySwarm has multiple samples associated with this activity.

 

206f27ae820783b7755bca89f83a0fe096dbb510018dd65b63fc80bd20c03261

ae9f7fce57c7b928e659dccf0e00fa79cd9cd61a106f18d4e03f92dc3a03c295

 

Don’t have a PolySwarm account? Go here to sign up for a free Community plan or subscribe.

Contact us at hivemind@polyswarm.io | Check out our blog | Subscribe to our reports.

 

Topics: Threat Bulletin, SharePoint vulnerabilities, Storm-2603, ToolShell, Warlock Ransomware, Longlegs

The Hivemind

Written by The Hivemind

Subscribe to Email Updates

Lists by Topic

see all

Posts by Topic

See all

Recent Posts