Ethical Hacking News
Warlock ransomware continues to exploit vulnerabilities in SharePoint to breach critical infrastructure operators worldwide. The group, known as Longlegs, has been targeting organizations in various countries, using a combination of techniques to gain initial access. This article provides an in-depth look at the methods used by Longlegs and the potential consequences of these attacks.
The Longlegs group, also known as Storm-2603, is exploiting unpatched vulnerabilities in SharePoint to breach critical infrastructure operators worldwide.The attackers are using a combination of techniques, including the exploitation of a chain of SharePoint zero-days dubbed ToolShell, to gain initial access.The group has targeted at least four organizations in the past two months, including a water utility, a telecom provider, and a regional government body.The attackers use webshells to gain access and then steal server ASP.NET machine keys to create a signed payload that can execute code.The attackers use DLL sideloading to run additional payloads and download files from legitimate hosting services to blend in with normal activity.The attackers spread out to more hosts by adding a fake-sounding admin account and deploying a tool to disable antivirus and EDR.The ransomware was delivered through normal domain replication traffic using the SYSVOL share.The Longlegs group's continued activity highlights the vulnerability of SharePoint and the need for organizations to patch their servers.
Warlock ransomware, a group of hackers, continues to exploit unpatched vulnerabilities in SharePoint to breach critical infrastructure operators worldwide. The group, known as Longlegs, also referred to as Storm-2603, has been targeting organizations in the US, Brazil, India, Russia, Taiwan, and Japan, as well as those in Portuguese and Spanish-speaking countries across Europe, Africa, and Latin America.
According to a recent report by Symantec, the attackers are using a combination of techniques, including the exploitation of a chain of SharePoint zero-days collectively dubbed ToolShell, to gain initial access to targeted organizations. The group has already targeted at least four organizations in the past two months, including a water utility, a telecom provider, a regional government body, and a university.
The attackers place a webshell in the LAYOUTS directory and design it to work across different SharePoint versions. They then steal the server's ASP.NET machine keys and use them to create a signed payload that can execute code inside the SharePoint application. This technique is effective, but it depends on finding SharePoint servers that have not been properly patched.
Once they get inside, the attackers use DLL sideloading to run additional payloads. They download these files from legitimate hosting services such as catbox.moe and wasabisys.com, which helps the traffic blend in with normal activity. The attackers also use a signed but vulnerable driver called K7RKScan to disable security software, and have installed Visual Studio Code's tunneling feature as a service, giving them remote access that can look like normal developer activity.
The attackers spread out to more hosts by adding a fake-sounding admin account named SPSEPRDSetup, a decent bit of social camouflage since SharePoint really does create accounts with that kind of prefix. They deployed a tool designed to disable antivirus and EDR across the network in a short period, and then deployed Warlock ransomware almost immediately after the security tools were disabled.
The attackers used the domain's SYSVOL share to distribute the ransomware. SYSVOL is automatically replicated across domain controllers, making it an effective way to spread files across a Windows domain. Symantec found that the ransomware was delivered through normal domain replication traffic, with three systems capturing dfsrs.exe, the Windows service responsible for that replication, delivering the malicious files.
The report states that "Longlegs' continued activity, more than a year after Warlock ransomware first came to prominence, shows that exploitation of ToolShell and other related-SharePoint vulnerabilities remains a viable initial access route for attackers." It also notes that the apparent recent focus on Portuguese- and Spanish-speaking countries suggests either an opportunistic targeting pattern driven by exposed, vulnerable SharePoint servers, or a more deliberate tasking.
The inclusion of critical infrastructure operators among the victims is a reminder of the potential real-world consequences of ransomware attacks that succeed against essential services. The report concludes that organizations running on-premises SharePoint Server and haven't checked it against CISA's July 2026 advisory should do so before their Monday coffee gets cold.
Related Information:
https://www.ethicalhackingnews.com/articles/Warlock-Ransomware-Continues-to-Exploit-Vulnerabilities-in-SharePoint-to-Hit-Critical-Infrastructure-Worldwide-ehn.shtml
https://securityaffairs.com/200304/malware/warlock-ransomware-still-exploits-year-old-sharepoint-flaws-to-hit-critical-infrastructure.html
Published: Sun Oct 4 03:36:43 2026 by llama3.2 3B Q4_K_M