Overview
- Security firms say the China‑linked Warlock operator, tracked as Longlegs or Storm‑2603, has hit a water utility, a telecom provider, a regional government body, and a university in Portuguese‑ and Spanish‑speaking countries.
- The group gains initial access by exploiting SharePoint flaws, including the ToolShell zero‑day chain, then installs web shells that extract ASP.NET machine keys to forge signed payloads for remote code execution.
- In an intrusion that began on July 22, 2026, researchers found the attacker used a signed vulnerable driver via a bring‑your‑own‑vulnerable‑driver technique to disable AV/EDR on about 40 hosts and then ran Warlock on roughly 33 machines.
- After initial access the actor stages ransomware in the domain SYSVOL share so files replicate to every domain controller, and it uses DLL sideloading, downloads from legitimate cloud hosts, and Visual Studio Code tunneling for covert remote access.
- The attacks show why organizations with on‑premises SharePoint must patch known CVEs, audit SYSVOL and Group Policy use, and monitor for signed but vulnerable drivers because successful breaches can quickly disrupt essential services and users.