<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=10643465&amp;fmt=gif">

China-Linked Warlock Ransomware Still Breaking Into Utilities

Warlock ransomware group exploits SharePoint flaws to attack critical infrastructure in Portuguese and Spanish-speaking regions.
Content Team

Symantec reports that the China-nexus group behind Warlock ransomware is still breaking into organizations through Microsoft SharePoint, a year after that route made its name. The group goes by Longlegs at Symantec and Storm-2603 at Microsoft. In the two months to October 1, it hit at least four organizations across Europe, Africa, and Latin America: a water utility, a telecom provider, a regional government body, and a university.

In one intrusion against a critical infrastructure operator, the attackers pushed an AV and EDR killing tool to at least 40 hosts inside about two hours, then ran Warlock on at least 33 of them. They staged the payload in the domain's SYSVOL share, so routine domain replication carried it everywhere at once.

The way in is on-premises SharePoint Server, not the cloud version. Once inside, the group plants a webshell and steals the farm's ASP.NET machine keys, then uses them to forge a signed payload. That changes what cleanup means: patching alone leaves stolen keys valid, so they have to be rotated too.

Security tools go down via a signed but vulnerable driver — K7RKScan in other recent Longlegs intrusions, unidentified in this one. For remote access the group installs Visual Studio Code's tunnel service, so the traffic reads like a developer's. Unpatched SharePoint servers remain the primary entry point. A year on, that still works.

Source: SecurityWeek

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo