CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →
← Back to the live brief
HIGHNATOB2threat

Longlegs (Storm-2603), the developer of Warlock ransomware, still enters through on-premises SharePoint: a water utility, a telecom, a regional government body and a university hit in two months

Symantec: Warlock's operator steals SharePoint machine keys, forges signed payloads and ships ransomware via SYSVOL

Defender actions

  • On every on-premises SharePoint Server farm that was reachable from the internet while unpatched, patch it and then rotate the ASP.NET machine keys and restart IIS on all SharePoint servers, as Microsoft's ToolShell guidance says, and look for unexpected .aspx files in the LAYOUTS template directories of every installed SharePoint version and for domain accounts named like SharePoint setup accounts in local Administrators groups.

Analysis

Symantec reports that Longlegs, also known as Storm-2603, develops the Warlock ransomware and attacked at least four organizations in two months: a water utility, a telecommunications provider, a regional government body and a university, in Portuguese- and Spanish-speaking countries (Symantec, 2026-10-01). Symantec says the group typically enters through on-premises SharePoint Server, and that the 2025 ToolShell flaws (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770 and CVE-2025-53771) likely remain in its arsenal alongside newer SharePoint flaws (Symantec, 2026-10-01); BleepingComputer relays the report (BleepingComputer, 2026-10-02).

In the intrusion Symantec walks through, the likely entry was SharePoint exploitation, and on 2026-07-22 PowerShell wrote a web shell into the SharePoint LAYOUTS template directory (Symantec, 2026-10-01). The group drops one into the directories of several SharePoint versions at once; it harvests the farm's ASP.NET machine keys, which the attackers use to forge a validly signed payload that runs code in the SharePoint application pool (Symantec, 2026-10-01). From 2026-07-28 PowerShell commands loading the System.Workflow.ComponentModel assembly, the deserialization gadget behind the forged payload, ran at intervals (Symantec, 2026-10-01). The attackers also used DLL sideloading, fetched installers with msiexec from legitimate cloud file-sharing services, enumerated domain accounts and trusts, added a setup-lookalike domain account to local Administrators on three more hosts, installed Visual Studio Code Insiders as a tunnel service, and ran NetExec for enumeration, credential spraying and remote execution (Symantec, 2026-10-01).

On 2026-07-31 a security-tool killer, pushed with one-line commands that copied a tool set from an internal share, ran on at least 40 hosts in about two hours; its driver is unknown, but in other recent attacks the group used the signed K7RKScan driver (CVE-2025-1055) (Symantec, 2026-10-01). Warlock then ran on at least 33 hosts from the domain's SYSVOL scripts share, with the DFS Replication service (dfsrs.exe) as the parent on three hosts, so SYSVOL replication delivered the payload (Symantec, 2026-10-01).

Exposure: on-premises SharePoint Server farms reachable from the internet or from an attacker's foothold that were unpatched against the ToolShell and later flaws; Symantec gives no version table (Symantec, 2026-10-01). Because the web shell takes the machine keys, patching alone does not replace them; Microsoft's ToolShell guidance says it is critical to rotate the machine keys and restart IIS on all SharePoint servers (Microsoft, 2025-07-22).

Triage: Visual Studio Code tunnels are ordinary on developer workstations; the observed pattern is a service installed from a system folder on a host in a domain already showing SharePoint exploitation or an unexpected administrator account (Symantec, 2026-10-01).

Cited evidence

In the past two months, Longlegs has attacked at least four organizations, including two critical infrastructure operators (a water utility and a telecommunications provider), a regional government body, and a university.

The webshell's function is to harvest the SharePoint farm's ASP.NET machine keys, which the attackers then use to forge a validly signed payload that achieves remote code execution inside the SharePoint application pool.

In one intrusion against a critical infrastructure operator, the attackers pushed a tool designed to disable security software to at least 40 hosts within about two hours, then deployed Warlock on at least 33 hosts by staging it in the domain's SYSVOL share, where ordinary domain replication delivered it to machines.

Symantec Threat Hunter Team / Carbon Black 2026-10-01

Sources3

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.