"In the past two months, Longlegs has attacked at least four organizations, including two critical infrastructure operators (a water utility and a telecommunications provider), a regional government body, and a university," the Broadcom-owned Symantec and Carbon Black Threat Hunter Team said.
Who Warlock (also tracked as Longlegs, Gold Salem, and Storm-2603) has struck
Symantec and Carbon Black report that the suspected China-linked threat actor known as Warlock has continued to target organizations with on-premises Microsoft SharePoint Server deployments. Victims identified in the reporting were located in Portuguese- and Spanish-speaking countries across Europe, Africa, and Latin America. The types of organizations named include critical infrastructure operators (specifically a water utility and a telecommunications provider), a regional government body, and a university.
ToolShell and SharePoint exploitation: the initial access chain
Warlock first rose to prominence in mid-2025 through the zero-day exploitation of the so-called "ToolShell" SharePoint flaws to deploy ransomware. The group has repeatedly leveraged multiple vulnerabilities in on-premises SharePoint Server environments. After gaining access, operators drop web shells that target multiple SharePoint versions. Those web shells are used to collect the SharePoint farm's ASP.NET machine keys, which the actors then abuse to forge a validly signed payload and achieve remote code execution inside the SharePoint application pool.

Nobody's watching your logs at 2 AM.
Full SOC coverage without building one. Nubivance deploys and manages Rapid7 InsightIDR and MDR for organizations that need detection and response, not another dashboard.
Get coverageTechniques for persistence, scale, and evasion
Across incidents, the actors have combined a range of tactics designed to move quickly and avoid detection:
- Using web shells to harvest ASP.NET machine keys and gain code execution inside the SharePoint application pool.
- DLL sideloading to load malicious code into memory.
- Downloading follow-on payloads from legitimate cloud file‑sharing and storage services such as catbox[.]moe and wasabisys[.]com to blend traffic with benign downloads.
- Abusing a legitimate-but-vulnerable driver, K7RKScan.sys (CVE-2025-1055), as a bring-your-own-vulnerable-driver (BYOVD) method to disable security software — a technique previously used by other ransomware actors.
- Employing living‑off‑the‑land tools, including the abuse of Microsoft Visual Studio Code's built‑in tunnel feature, to facilitate remote connections to infected systems.
- Staging payloads inside the compromised domain's SYSVOL share to leverage ordinary domain replication and deploy ransomware at scale.
July 22, 2026 activity and an intrusion that moved fast
Symantec and Carbon Black recount a recent intrusion pattern in which the adversary acted rapidly: in one incident the attackers pushed a tool designed to disable security software to at least 40 hosts within about two hours, then deployed Warlock on at least 33 hosts by staging it in the domain's SYSVOL share so that domain replication delivered it to machines. As recently as July 22, 2026, the actors exploited SharePoint Server flaws to drop a web shell, conduct discovery, obtain arbitrary code execution inside the SharePoint application pool, deploy additional payloads, establish VS Code tunnels, terminate security software, and ultimately deploy the ransomware binary.
What this means for critical infrastructure operators, regional governments, and universities
Critical infrastructure operators — such as the water utility and telecommunications provider named in the report — should note the speed and scale of the intrusion described: staging in SYSVOL and the disabling of security software enabled lateral spread and mass deployment within hours. The report underscores exposure to unpatched on‑premises SharePoint instances.
Regional governments and universities face the same technical pathway: vulnerable SharePoint deployments and accessible SYSVOL shares give operators a route to distribute payloads broadly. The actors’ use of legitimate cloud hosting for follow-on payloads and VS Code tunnels also complicates straightforward network‑based detection.
Across all affected organizations the reporting reiterates a simple operational fact from the investigators: exploitation of ToolShell and related SharePoint vulnerabilities remains a viable initial access route for SharePoint deployments that have not been patched or otherwise mitigated.
More than a year after Warlock ransomware first came to prominence, the group's continued activity — and the apparent recent focus on Portuguese‑ and Spanish‑speaking countries — raises a pointed choice for defenders: remediate exposed SharePoint servers and monitor for the specific tactics observed, or leave a well‑documented avenue for rapid, large‑scale compromise open to operators who have demonstrated they can move from compromise to mass deployment in hours.




