Cyber News
Fake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA Codes
Category: Phishing / Artificial Intelligence

Threat Actor: Warlock / Longlegs / Storm-2603 / Gold Salem

A suspected China-linked threat actor tracked as Warlock, also known as Longlegs and Storm-2603, is continuing to exploit vulnerabilities in on-premises Microsoft SharePoint Server environments to gain initial access, disable security controls, move laterally, and deploy ransomware.
According to research from the Symantec and Carbon Black Threat Hunter Team, the recent campaign has affected at least four organizations in Portuguese- and Spanish-speaking countries across Europe, Africa, and Latin America. The victims included a water utility, telecommunications provider, regional government organization, and university.
The campaign demonstrates how a single vulnerable internet-facing SharePoint server can become the entry point for a much broader domain-wide ransomware attack.

The observed attack chain follows several stages:
SharePoint exploitation → Web shell → Credential/key theft → Remote code execution → Reconnaissance → Lateral movement → Security-tool disabling → Ransomware deployment
Warlock has continued to use vulnerabilities affecting on-premises Microsoft SharePoint Server deployments.
The threat actor gained access by exploiting SharePoint flaws and subsequently placing a web shell within the SharePoint environment.
The attackers then targeted the SharePoint application's ASP.NET machine keys. These keys can be abused to forge validly signed payloads and achieve remote code execution within the SharePoint application pool.
The campaign is associated with the broader ToolShell exploitation activity that brought Warlock to prominence in 2025.
After gaining access, attackers deployed web shells designed to work across multiple SharePoint versions.
The web shell provided a foothold for additional commands and allowed the attackers to progress from the compromised SharePoint server toward broader network access.
Observed activity included:
PowerShell execution
System and domain reconnaissance
SharePoint application-pool code execution
Downloading additional payloads
Active Directory enumeration
Credential-related activity
Lateral movement
Rather than relying exclusively on custom malware, the attackers used legitimate Windows utilities to perform reconnaissance and execute commands.
Observed tools included:
whoami
net
nltest
PowerShell
msiexec
NetExec
This approach can make malicious activity more difficult to distinguish from legitimate administrative operations.
For SOC teams, the important signal is often not the presence of these tools individually, but the sequence and context in which they are executed.
For example:
SharePoint worker process → PowerShell → reconnaissance → payload download → domain enumeration → remote access → security-tool termination
That sequence is considerably more suspicious than an isolated administrative command.
The attackers also used DLL sideloading to execute malicious code through legitimate executable files.
This technique can allow malicious code to execute while appearing to originate from a trusted or expected binary.
The observed intrusion included executable/DLL pairs such as:
ssvagent.exe
logger.exe
doexe.exe
doexeloc.dll
This activity highlights the importance of monitoring unusual executable/DLL relationships rather than relying only on known malware hashes.
Warlock also downloaded follow-on payloads from legitimate cloud-hosting and file-sharing infrastructure.
Researchers observed infrastructure associated with services including:
catbox[.]moe
wasabisys[.]com
Using legitimate hosting providers can provide attackers with an additional layer of operational camouflage because connections to popular cloud services may not immediately appear malicious.
SOC teams should therefore correlate process execution + outbound connection + downloaded file + subsequent behavior, rather than automatically trusting a destination because it belongs to a legitimate hosting provider.
One of the most concerning stages of the attack involved Bring Your Own Vulnerable Driver (BYOVD).
The attackers were observed abusing K7RKScan.sys, a legitimate signed but vulnerable driver associated with CVE-2025-1055, to interfere with security software.
The purpose was to neutralize defensive controls before ransomware deployment.
This is particularly dangerous because the attacker does not necessarily need to exploit a new kernel vulnerability. Instead, they can abuse a legitimately signed vulnerable driver to obtain capabilities that allow them to terminate or interfere with protected security processes.
Another notable technique was the abuse of Visual Studio Code's tunnel functionality.
The attackers installed a VS Code Insiders binary as a service and used its tunnel functionality to establish remote connectivity to compromised systems.
Because Visual Studio Code is legitimate software and its infrastructure is associated with Microsoft, this technique can potentially blend into normal enterprise traffic.
For defenders, this reinforces the need to monitor:
Unexpected VS Code installations
code-insiders.exe running as a service
Tunnel creation on servers
Developer tools appearing on non-development systems
Unusual outbound connections initiated by server processes
The attackers eventually moved from individual compromised hosts to domain-wide ransomware deployment.
One particularly notable technique involved staging ransomware payloads inside the domain's SYSVOL share.
SYSVOL is normally used by Active Directory to distribute files associated with Group Policy and logon processes.
Because SYSVOL is replicated between domain controllers and accessible across the domain, attackers can abuse it as a distribution mechanism.
In one observed intrusion:
Security-disabling tools were pushed to at least 40 hosts
Warlock ransomware subsequently appeared on at least 33 hosts
Ransomware payloads were staged through the domain's SYSVOL infrastructure
This allowed the attackers to move from compromising a small number of systems to impacting a significant portion of the environment in a short period.
A simplified representation of the observed campaign is:
Internet-facing SharePoint Server
↓
SharePoint vulnerability exploitation
↓
Web shell deployment
↓
ASP.NET machine-key abuse
↓
Remote Code Execution
↓
PowerShell / Windows reconnaissance
↓
Payload download
↓
DLL sideloading
↓
Active Directory enumeration
↓
Lateral movement
↓
VS Code Tunnel / remote access
↓
BYOVD / security-tool termination
↓
SYSVOL payload staging
↓
Domain-wide ransomware deployment

The campaign demonstrates that ransomware operations are increasingly combining vulnerability exploitation, legitimate administrative tools, defense evasion, and domain-level deployment mechanisms.
The initial compromise may begin with a single exposed SharePoint server, but the final impact can extend across an organization's entire Active Directory environment.
The use of SYSVOL is particularly significant because it provides attackers with a mechanism for distributing malicious files at scale.
The campaign also shows why simply detecting the ransomware binary may be too late. By the time ransomware is executed, attackers may already have:
Compromised an internet-facing server
Established persistence
Enumerated the domain
Obtained credentials or authentication material
Moved laterally
Disabled security products
Prepared ransomware distribution
Organizations running on-premises SharePoint should prioritize monitoring for:
Unexpected .aspx files in SharePoint directories
Web shells
Suspicious SharePoint worker-process activity
Unexpected PowerShell spawned by SharePoint processes
ASP.NET machine-key-related anomalies
Outbound connections initiated by SharePoint servers
Unsigned or unusual DLL loading
DLL sideloading patterns
msiexec.exe downloading packages from external URLs
Suspicious PowerShell execution
Unexpected code-insiders.exe activity
VS Code tunnel creation on servers
Security products unexpectedly stopping or being disabled
Monitor unusual execution of:
nltest
net
NetExec
Remote administrative commands
Unexpected local administrator-group modifications
Newly created or suspiciously named accounts
SOC teams should pay particular attention to unexpected files appearing in:
\\<domain>\SYSVOL\
Especially:
.exe
.dll
.bat
.ps1
.cmd
Unknown scripts or binaries
Unexpected executable files in SYSVOL should be treated as a high-priority investigation.
1. Patch internet-facing SharePoint servers quickly.
SharePoint vulnerabilities can provide attackers with an initial foothold into the enterprise.
2. Do not rely only on malware signatures.
Warlock's activity includes legitimate tools and native Windows utilities.
3. Monitor defense-evasion behavior.
Unexpected attempts to terminate EDR/AV processes or load vulnerable drivers should generate high-priority alerts.
4. Protect Active Directory and SYSVOL.
Once attackers obtain domain-level access, SYSVOL can become an effective mechanism for distributing malicious payloads.
5. Investigate attack chains, not isolated alerts.
A single whoami or nltest command may be legitimate. The same commands following SharePoint exploitation and web-shell activity are significantly more concerning.

The continued activity associated with Warlock/Longlegs shows that unpatched SharePoint infrastructure remains a valuable entry point for ransomware operators.
The most important lesson for defenders is that ransomware deployment is often the final stage of a much longer intrusion.
Organizations should focus on detecting the earlier stages of the attack chain—SharePoint exploitation, web shells, suspicious PowerShell, DLL sideloading, Active Directory reconnaissance, vulnerable-driver abuse, and unusual SYSVOL activity—before attackers reach the ransomware deployment stage.
According to Symantec and Carbon Black, the recent activity represents continued exploitation of SharePoint vulnerabilities more than a year after Warlock first became prominent.
T1190 — Exploit Public-Facing Application
T1505.003 — Web Shell
T1059.001 — PowerShell
T1574.002 — DLL Side-Loading
T1087.002 — Domain Account Discovery
T1018 — Remote System Discovery
T1489 — Service Stop
T1562.001 — Impair Defenses
T1078 — Valid Accounts
T1021 — Remote Services
T1105 — Ingress Tool Transfer
T1486 — Data Encrypted for Impact
Continue reading
Cyber News
Category: Phishing / Artificial Intelligence

Cyber News
Severity: High CVSS: 8.7 Affected Products: Citrix NetScaler ADC & NetScaler Gateway Attack Type: Denial of Service / Possible Remote Code Execution

Cyber News
Category: Cybercrime / Data Breach Focus: Threat Intelligence, Cybercrime, Data Theft, Extortion, Cloud Security, Incident Investigation

3 entries, most recent posts.
Level: Intermediate

Category: Phishing / Artificial Intelligence

Severity: High CVSS: 8.7 Affected Products: Citrix NetScaler ADC & NetScaler Gateway Attack Type: Denial of Service / Possible Remote Code Execution
