The China-nexus group behind Warlock ransomware, tracked as Longlegs and Storm-2603, has shifted toward fewer, higher-value targets in Spanish- and Portuguese-speaking countries. According to Symantec findings reported by WaterISAC, the group attacked at least four organizations across Europe, Africa, and Latin America over the preceding two months: a water utility, telecommunications provider, regional government body, and university. The attackers exploit on-premises Microsoft SharePoint vulnerabilities for initial access, then use DLL sideloading, a vulnerable signed driver to disable security tools, and living-off-the-land techniques.
Warlock operators stage ransomware in a domain controller’s SYSVOL share, using normal Active Directory replication to distribute the payload across domain controllers. This approach may evade detections focused on conventional remote execution. WaterISAC recommends verifying SharePoint patches, treating previously exposed servers as potentially compromised, monitoring SYSVOL and domain controllers, and restricting unnecessary remote tunneling. The accompanying vulnerability references identify SharePoint flaws CVE-2025-49706 and CVE-2025-53770; defenders should include these in remediation checks rather than assume patching alone rules out an existing compromise.

See which actors are running it and whether you're in range.
3 events from the most recent confirmed update back to the earliest known activity.
WaterISAC published an alert describing Warlock's SharePoint exploitation and staging of ransomware in a domain controller's SYSVOL share, allowing Active Directory replication to distribute the payload. It recommended verifying SharePoint patches, investigating previously exposed servers, monitoring domain controllers and SYSVOL, and restricting unnecessary remote tunneling.
During the early hours of July 31, Longlegs distributed an AV/EDR-killing utility that executed on at least 40 additional hosts within approximately two hours during a critical infrastructure intrusion. Warlock followed almost immediately, with ransomware binaries and ransom notes recorded on at least 33 hosts.
Symantec reported that the China-nexus Warlock group, tracked as Longlegs and Storm-2603, attacked at least four organizations during the preceding two months, including a water utility, telecommunications provider, regional government body, and university. The campaign reflected a shift toward fewer, higher-value targets in Spanish- and Portuguese-speaking countries.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
4 references tracked. Mallory keeps watching after this page renders.
blog.polyswarm.io
Open sourcewaterisac.org
Open sourcecve.org
Open sourcecve.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.