
Symantec and Carbon Black researchers report that the China-linked Warlock ransomware operation, which Symantec tracks as Longlegs and Microsoft linked to Storm-2603, has spent the past two months attacking Portuguese- and Spanish-speaking countries across Europe, Africa and Latin America. Confirmed victims include a water utility, a telecommunications provider, a regional government body and a university. Initial access came through on-premises SharePoint servers, where the group dropped a web shell built to work across several SharePoint versions. The 2025 “ToolShell” chain (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770 and CVE-2025-53771) is still working against unpatched servers, and Symantec says the attacks now also use newer 2026 SharePoint vulnerabilities.
In the intrusion that began on July 22, the attacker did reconnaissance two days later, then used a signed but vulnerable K7RKScan driver (CVE-2025-1055) in a bring-your-own-vulnerable-driver attack to disable security software on at least 40 hosts in about two hours. The ransomware was staged in the domain’s SYSVOL share, which every domain controller replicates, and Warlock launched on at least 33 hosts almost as soon as protection went down on July 31. The attackers also installed Visual Studio Code Insiders as a service for remote tunneling and used the NetExec framework for Active Directory enumeration and credential spraying, tools that blend in with normal admin traffic. Symantec says the focus on these regions may be opportunistic, driven by exposed servers, or deliberate tasking.
How to check if you’re affected
Affected products are internet-facing, self-managed Microsoft SharePoint Server deployments. Affected versions are any not patched for the 2025 ToolShell CVEs listed above or the newer 2026 SharePoint fixes (see CISA’s SharePoint hardening alert linked below).
- Patch and rotate: confirm the SharePoint security updates are installed, and if a server was exposed unpatched, rotate its machine keys and service credentials, since web-shell access can persist after patching.
- Hunt for the tooling: look for the K7RKScan driver (
K7RKScan.sys) loading on servers, Visual Studio Code Insiders installed as a Windows service, NetExec activity, and unexpected files or logon scripts in the SYSVOL share. Symantec’s report includes file and infrastructure indicators of compromise. - Harden EDR: enable your endpoint product’s tamper protection and block known vulnerable drivers (Microsoft’s recommended driver block list) so a driver-based EDR killer fails.
