3 OCT 2026 — A year ago, the group behind Warlock ransomware broke into organisations through a chain of flaws in Microsoft's SharePoint server software, known as ToolShell, that had no patch at the time. One of them, CVE-2025-53770, lets an attacker run code on an on-premises SharePoint server over the network. Patches have long since shipped. New research from Symantec shows the same group still getting in through SharePoint, and in the past two months it has hit a water utility and a telecoms provider.
Symantec tracks the China-linked group as Longlegs; Microsoft calls it Storm-2603. The latest victims, at least four organisations, were in Portuguese- and Spanish-speaking countries across Europe, Africa and Latin America.
Who was hit
Besides the water utility and the telecoms provider, the victims were a regional government body and a university, according to Symantec's report. Symantec does not name them. It notes that Warlock has previously been used against organisations in the United States, Brazil, India, Russia, Taiwan and Japan, and that the recent concentration could be opportunistic, driven by exposed servers, or deliberate.
How one intrusion unfolded
In the attack Symantec describes in detail, the victim was a critical infrastructure operator and the first sign was a web shell planted on a SharePoint server on 22 July 2026. The attackers used it to steal the server's cryptographic machine keys, which let them forge signed requests that SharePoint would then run as code.
Over the following week they moved through the network. They added a disguised account to the administrators group on several machines, ran an open-source penetration-testing tool to map the domain and spray passwords, and installed Microsoft's own Visual Studio Code as a service to use its built-in tunnel for remote access. Because that tool is signed by Microsoft and relays through Microsoft's servers, its traffic can look like an ordinary developer's.
The final hours
Early on 31 July, the attackers pushed a tool that disables security software out to at least 40 machines within about two hours. In other recent attacks the group has done this by abusing K7RKScan, a signed but vulnerable driver, a technique known as bringing your own vulnerable driver. Warlock appeared on each machine almost as soon as its protection was switched off, reaching at least 33.
To spread the ransomware, the attackers placed it in the domain's SYSVOL share, a folder that is copied automatically to every domain controller. On three machines, Symantec found records showing the ransomware arriving through that ordinary replication, rather than being pushed to each one.
Why old flaws still work
Symantec says exploiting ToolShell and related SharePoint flaws remains a viable way into deployments that have not been patched or otherwise mitigated. Stolen machine keys are a particular risk because, as we reported in July, they can survive a patch unless they are rotated.
BleepingComputer notes that Microsoft observed state-backed groups and Storm-2603 using ToolShell exploits in 2025. Symantec has published file hashes and infrastructure linked to the attacks.
What defenders can check
Organisations running on-premises SharePoint can check that the ToolShell patches are installed, rotate the server's machine keys, and look for unexpected files in its LAYOUTS directory. Other signs from this campaign include Visual Studio Code tunnels running as a service on servers and executables appearing in SYSVOL's scripts folder.