A China-linked threat actor known as Warlock—also tracked as Longlegs or Storm-2603—has unleashed a string of assaults in Portuguese- and Spanish-speaking countries by exploiting known vulnerabilities in on-premises Microsoft SharePoint servers. Its targets include critical infrastructure operators like water utilities and telecoms, along with universities and regional governments. Despite fixes being available since July 2025, many SharePoint environments remain dangerously exposed.
ToolShell Vulnerabilities: Why They’re Still a Threat
The attacks revolve around a set of SharePoint flaws collectively dubbed “ToolShell” (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, CVE-2025-53771). ToolShell enables unauthenticated remote code execution against internet-facing SharePoint Server setups, including deserialization attacks that let attackers upload web shells and steal cryptographic keys. Even servers patched after the original disclosures remain vulnerable if ASP.NET machine keys have not been rotated, since stolen keys allow attackers to impersonate legitimate traffic.
A Rapid, Coordinated Attack Chain
Recent incidents stretched over about two months, during which Warlock breached at least four organizations—a water utility, a telecommunications provider, a regional government, and a university—all in Portuguese- or Spanish-speaking regions across Europe, Africa, and Latin America. One notable intrusion began on July 22, 2026, and concluded by July 31. Within hours attackers had shut down endpoint security tools on dozens of hosts, then rolled out Warlock across 33 machines via the SYSVOL share.
Warlock’s toolkit is a mix of both bespoke and hijacked components. Web shells provide persistence; key theft enables sophisticated payload forgery; behavior-based evasion tools like VS Code’s remote tunnel feature are used for stealthy command and control; and a legitimate but vulnerable driver (K7RKScan.sys, CVE-2025-1055) serves as a kernel-level weapon in disabling protections.
Mitigations and Lessons Misapplied
Microsoft issued patches in July 2025 that addressed all four ToolShell vulnerabilities in SharePoint Server Subscription Edition, 2019, and 2016. However, the mere application of fixes didn’t end all risk—many compromised servers hadn’t rotated ASP.NET machine keys, hunted for web shells, or checked for persistence, which are essential steps when dealing with post-exploitation threat follow-up.
Organizations are also warned to inventory all internet-facing SharePoint servers, verify whether SharePoint Online is involved (which isn’t affected by these CVEs), and treat even patched environments with suspicion if they were exposed. Monitoring behavior like anomalous use of scheduled tasks, unexpected service installs, or content staged in SYSVOL may provide early indictors of compromise.
In one breach, attackers disabled endpoint detection and response (EDR) tools on at least 40 hosts in roughly two hours, then used SYSVOL to push the ransomware payload to 33 systems simultaneously. Using legitimate infrastructure (Group Policy Objects, domain replication) boosted their ability to scale quickly.
The recent target set—service-based entities in Spanish- and Portuguese-speaking regions—could reflect both opportunistic exploitation of exposed SharePoint instances and more intentional targeting. The actor continues to overlap with groups previously labeled CL-CRI-1040, CamoFei, and ChamelGang, sharing tradecraft and maybe ideology.
What this means: defenders can’t assume patching alone solves this. Persistent threats like Warlock evolve rapidly, and publicly disclosed vulnerabilities—if not followed by proper configuration and threat hunting—leave doorways open.
Analytical angle:Warlock’s operations expose a recurring gap in enterprise security: remediation delay and insufficient follow-up. It’s not enough to install patches; firms must treat exposure windows as invitations to breach. The use of signed vulnerable drivers, stolen machine keys, and SYSVOL-based propagation shows that attackers will leverage both infrastructure and legacy mistakes to catastrophic effect. For organizations operating in sectors like utilities or telecom—where network disruption has outsized impact—this pattern demands urgent action. Watch for indicators tied to SYSVOL staging, driver abuse, and SharePoint-derived web shells across your domain.