A ransomware crew tied to China is still breaking into SharePoint servers that defenders never patched, and Symantec says the door remains wide open.
The group is tracked as Longlegs and Storm-2603, and it runs the Warlock ransomware family. Its preferred entry point is the ToolShell collection of SharePoint flaws that state-linked intruders used as zero-days in 2025, along with newer bugs including CVE-2026-32201 and CVE-2026-45659.
Portuguese- and Spanish-speaking countries account for at least four of the targets Symantec lists over the past two months, among them a water utility and a telecommunications provider, alongside two critical infrastructure operators, a university and a regional government body.
During a single intrusion, the hackers first deployed a tool that switched off security protections across at least 40 systems, and Warlock then detonated on 33 of them.
The playbook that follows is consistent. After exploiting SharePoint the intruders drop web shells, lift ASP.NET machine keys, and plant a signed payload for remote code execution. They lean on DLL sideloading and living-off-the-land commands, and they have installed Microsoft’s code-insiders.exe binary as a service to build a covert tunnel through Visual Studio Code traffic. To spread the encryption widely, they stage the ransomware in a domain’s SYSVOL share, which replicates it to every domain controller.
More than a year after Warlock first appeared, Symantec warns that SharePoint flaws still give attackers a viable way in wherever servers go unpatched.
