Warlock ransomware, linked to the China-based Longlegs and Storm-2603 cluster, continues to exploit SharePoint vulnerabilities to breach critical infrastructure, government, and education targets. Recent attacks have affected victims across multiple regions, with the group using webshells, payload staging, and security tool tampering to enable large-scale encryption. #Warlock #Longlegs #Storm2603 #SharePoint #ToolShell
Keypoints
- Warlock keeps targeting SharePoint servers in high-value organizations.
- Storm-2603 is linked to the China-based Longlegs hacking group.
- ToolShell exploitation has been a major initial access route.
- The attackers disable security tools and deploy Warlock across many systems.
- The group also uses DLL sideloading, webshells, and Visual Studio Code tunnels.