A cyber threat actor linked to China is actively exploiting vulnerabilities in Microsoft SharePoint Server to deploy Warlock ransomware. Recent incidents have impacted vital service providers and public sector entities in regions where Portuguese and Spanish are predominantly spoken.
Threat Actor Activity and Identification
This threat actor, known as Longlegs by Symantec and Storm-2603 by Microsoft, has previously been associated with other aliases like CL-CRI-1040, CamoFei, and ChamelGang. Over the past two months, they have successfully breached at least four organizations, including a water utility, a telecom company, a regional government, and a university across Europe, Africa, and Latin America.
Exploitation of SharePoint Vulnerabilities
The Warlock ransomware first emerged in June 2025, gaining notoriety for its deployment via the SharePoint “ToolShell” exploit chain. This chain includes vulnerabilities identified as CVE-2025-49704 and CVE-2025-49706, with further bypasses tagged as CVE-2025-53770 and CVE-2025-53771. These exploits allow unauthorized access to on-premises SharePoint servers, exposing configurations and enabling remote code execution. Despite patches, newer SharePoint vulnerabilities disclosed in 2026 continue to be exploited.
Technical Details and Defensive Measures
Research by Symantec reveals that Longlegs typically installs an ASPX webshell in the SharePoint LAYOUTS directory to target multiple product versions simultaneously. This webshell extracts ASP.NET machine keys, allowing attackers to craft signed __VIEWSTATE payloads for code execution within the SharePoint application pool. Subsequent malware is introduced via DLL sideloading, with installers sourced from legitimate cloud services like Catbox and Wasabi to camouflage malicious activity.
In a significant breach recorded on July 22, 2026, attackers deployed a webshell on a SharePoint server. They executed commands such as whoami and net user /domain while using NetExec for Active Directory exploration. This attack included deploying Microsoft-signed code-insiders.exe as a service and exploiting Visual Studio Code’s tunnel function for covert access.
Impact and Recommendations
The rapid spread of Warlock ransomware across at least 33 systems underscores the critical nature of cyber defense. Infected systems had files like run.exe, rune.exe, and ransom notes distributed via the SYSVOL share, exploiting the trusted infrastructure to propagate the ransomware. This campaign highlights the inadequacy of patching alone against potential SharePoint exploitations. Security experts advise proactive measures such as hunting for webshells, rotating machine keys, enabling AMSI in Full Mode, and restricting SharePoint’s internet exposure.
For sectors like water, telecom, and government, delayed remediation could lead to widespread operational disruptions. Immediate asset discovery, containment, and recovery planning are essential to counteract these sophisticated threats.
