The Warlock ransomware operation continues to exploit SharePoint vulnerabilities in attacks against critical infrastructure, government, and education organizations, according to new research from Symantec.
Warlock is believed to be run by a China-based threat actor tracked as Longlegs and Storm-2603, a group also linked to prior activity clustered under the names CL-CRI-1040, CamoFei, and ChamelGang. Last year, Chinese state-sponsored groups Linen Typhoon and Violet Typhoon were observed exploiting two SharePoint vulnerabilities known as ToolShell as zero-days, weeks before public disclosure. The exploitation wave ultimately compromised more than 400 SharePoint servers, with Storm-2603’s activity standing out amid broader APT exploitation.
By October 2025, researchers had tied numerous Warlock ransomware intrusions to ToolShell exploitation, with victims including a Middle East telecom firm, government entities in Africa and South America, and a US university.
Expanded Exploit Arsenal
Symantec’s latest report finds Storm-2603 still favors SharePoint bugs for initial access. Beyond ToolShell, the group’s toolkit may now include additional flaws tracked as CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, CVE-2026-58644, CVE-2026-50522, and CVE-2026-55040.
Over the past two months, Warlock operators hit at least four organizations in Portuguese- and Spanish-speaking countries, including two critical infrastructure operators (a water utility and a telecommunications provider), a regional government body, and a university. In one intrusion, the group disabled security software on at least 40 systems and then deployed Warlock ransomware on at least 33 of them.
Attack Chain Details
Exploitation of SharePoint flaws is typically followed by webshell deployment, theft of ASP.NET machine keys, and delivery of a forced-signed payload for remote code execution. Storm-2603 uses DLL sideloading for in-memory execution, pulls additional payloads from legitimate file-sharing services, deploys a vulnerable driver to disable security tools, and relies on living-off-the-land binaries for reconnaissance and command execution.
The group has also been seen abusing Visual Studio Code’s built-in tunnel feature, installing the code-insiders.exe binary as a service to create covert remote access that blends into normal developer and admin traffic. To scale ransomware deployment, Storm-2603 stages the Warlock payload inside a domain’s SYSVOL share, which replicates automatically to every domain controller and is readable domain-wide.
Symantec notes that Longlegs’ sustained activity, more than a year after Warlock first emerged, confirms that unpatched or unmitigated SharePoint deployments remain a viable initial access route for attackers.
