Longlegs, also tracked as Storm-2603, is a China-based threat actor that develops and deploys Warlock ransomware, which emerged in June 2025. Its earlier activity has been linked to the CL-CRI-1040, CamoFei, and ChamelGang clusters, whose historical operations included ransomware and espionage. Chinese state sponsorship has not been established, and the actor's dominant motivation remains undetermined. Longlegs targets organizations internationally, with documented victims in the United States, Brazil, India, Russia, Taiwan, and Japan. Recent operations affected water utilities, telecommunications providers, regional government bodies, and universities in Portuguese- and Spanish-speaking countries across Europe, Africa, and Latin America. The actor primarily obtains initial access by exploiting on-premises Microsoft SharePoint Server vulnerabilities, including the ToolShell chain and its patch-bypass variants: CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771. It deploys webshells, steals ASP.NET machine keys, and forges signed ViewState payloads for remote code execution. Post-compromise activity includes DLL sideloading, Active Directory reconnaissance, credential spraying, administrative privilege expansion, and lateral movement using PowerShell, NetExec, and other legitimate utilities. Longlegs also abuses Visual Studio Code tunneling for persistent remote access and legitimate cloud-hosting services for payload delivery. Before deploying ransomware, Longlegs disables endpoint protection through security-process termination and bring-your-own-vulnerable-driver techniques, including abuse of K7RKScan associated with CVE-2025-1055. It stages Warlock payloads in Active Directory's SYSVOL share, leveraging normal Distributed File System Replication for distribution. In a documented July 2026 intrusion, a security-disabling utility executed on at least 40 additional hosts within approximately two hours, followed by Warlock deployment on at least 33 systems.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
31 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
5 CVEs this actor has used in observed campaigns. 5 of them exploited in the wild.
The original ToolShell exploit chain involved CVE-2025-49704 and CVE-2025-49706, with subsequent exploitation activity involving the related CVE-2025-53770 and CVE-2025-53771 vulnerabilities.
The original ToolShell exploit chain involved CVE-2025-49704 and CVE-2025-49706. These flaws provided attackers with a path from an exposed SharePoint server to remote code execution and further compromise of the underlying environment.
The original ToolShell exploit chain involved CVE-2025-49704 and CVE-2025-49706. These flaws provided attackers with a path from an exposed SharePoint server to remote code execution and further compromise of the underlying environment.
The original ToolShell exploit chain involved CVE-2025-49704 and CVE-2025-49706, with subsequent exploitation activity involving the related CVE-2025-53770 and CVE-2025-53771 vulnerabilities.
Symantec has observed the group abusing the signed but vulnerable K7RKScan driver, associated with CVE-2025-1055, to terminate protected security processes at the kernel level before ransomware deployment.
28 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
China-based actor assessed by Symantec to develop and deploy Warlock ransomware. Recent attacks affected water, telecommunications, government, and education organizations. Its operations progress from SharePoint exploitation to credential reconnaissance, lateral movement, endpoint-security disruption, and ransomware deployment. In one intrusion, an AV/EDR-killing utility executed on at least 40 additional hosts within approximately two hours, and Warlock reached at least 33 systems through abused SYSVOL replication. The content does not establish Chinese state sponsorship.
China-nexus group deploying Warlock ransomware against organizations in Spanish- and Portuguese-speaking countries. Its recent campaign favors fewer, higher-value victims, including a water utility, telecommunications provider, regional government body, and university. It exploits on-premises SharePoint vulnerabilities for initial access and stages ransomware in SYSVOL so Active Directory replication distributes the payload across domain controllers.
The content describes Longlegs as a China-linked, state-sponsored actor deploying Warlock ransomware. It reportedly compromised at least four organizations across Portuguese- and Spanish-speaking countries, including water distribution, telecommunications, regional government, and education. A July 2026 intrusion progressed from SharePoint exploitation to domain-wide access, security-tool disabling on at least 40 hosts, and ransomware deployment on at least 33 hosts. These claims are extracted from the supplied content, not independently verified.
Operates Warlock ransomware and continues exploiting unpatched on-premises SharePoint servers through ToolShell and related flaws. Recent victims include a water utility, telecom provider, regional government body, and university in unspecified Portuguese- or Spanish-speaking countries. In one documented intrusion, the attackers disabled security software on at least 40 hosts within approximately two hours and deployed Warlock on at least 33 hosts through SYSVOL replication. The report connects Longlegs to older China-nexus clusters but does not explicitly establish state sponsorship.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.