Dev News Daily ENDE

Symantec: Warlock ransomware group still enters through SharePoint, now hitting water and telecoms

The group behind Warlock ransomware is still breaking into organisations through on-premises Microsoft SharePoint servers, Symantec's threat intelligence team reported on 1 October. In the past two months it attacked at least four organisations in Portuguese- and Spanish-speaking countries across Europe, Africa and Latin America: a water utility, a telecommunications provider, a regional government body and a university.

Symantec tracks the group as Longlegs, also known as Storm-2603, describes it as China-nexus and links it to older clusters known as CL-CRI-1040, CamoFei and ChamelGang. Warlock appeared in June 2025 and became known weeks later through the ToolShell SharePoint zero-days (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770 and CVE-2025-53771). Symantec expects those to remain in use alongside the newer SharePoint flaws that CISA warned about in July 2026.

How the intrusion worked. In the case Symantec reconstructs, a webshell was written into SharePoint's LAYOUTS directory on 22 July, for several SharePoint versions at once so that it would run whichever was installed. Its job was to read the farm's ASP.NET machine keys. With those keys the attackers forged a validly signed __VIEWSTATE payload and got code execution inside the SharePoint application pool on 28 July. Follow-on packages came from public hosting on catbox.moe and Wasabi, three of them within ninety minutes.

Moving through the network. The attackers added a domain account named SPSEPRDSetup, chosen to look like a SharePoint service account, to local administrators on further hosts. On one machine they installed Microsoft's own VS Code Insiders binary as a service and used its built-in tunnel for remote access, traffic that relays through Microsoft infrastructure and resembles a developer's. To blind defences they loaded K7RKScan, a signed but vulnerable driver (CVE-2025-1055) that can kill protected security processes from the kernel.

The final stage. In one critical infrastructure intrusion the security-killing tool reached at least 40 hosts in about two hours. Warlock was then staged in the domain's SYSVOL share, which Windows replicates to every domain controller and which every domain machine can read, and ran on at least 33 hosts.

Symantec: Warlock ransomware group still enters through SharePoint, now hitting water and telecoms
Symantec: Warlock ransomware group still enters through SharePoint, now hitting water and telecoms — Dev News Daily

What it means

The entry point is not new, and that is the warning: a year after ToolShell, on-premises SharePoint is still the door. Machine keys stolen from a compromised farm stay valid until they are rotated, so patching alone does not end an intrusion. Defenders can also watch for things that look legitimate here: a VS Code tunnel installed as a service on a server, a vulnerable signed driver loading, and executables appearing in SYSVOL.