Warlock Ransomware Attackers Hit Water and Telecom Operators

Warlock Ransomware Attackers Hit Water and Telecom Operators

Longlegs, a China-nexus threat actor tracked by Symantec, is using Microsoft SharePoint vulnerabilities and the Warlock ransomware to compromise organizations across multiple regions. The campaign has hit critical infrastructure, government, and university victims, while also abusing a vulnerable driver, Visual Studio Code tunneling, and SYSVOL to disable defenses and deploy payloads at scale. #Warlock #Longlegs #Storm2603 #ToolShell #K7RKScan #SharePoint #SYSVOL

Keypoints

  • Longlegs, also known as Storm-2603, is the China-nexus group Symantec links to the Warlock ransomware operation.
  • The group initially gained prominence by exploiting Microsoft SharePoint “ToolShell” vulnerabilities for initial access.
  • In the past two months, at least four organizations were targeted, including a water utility, a telecommunications provider, a regional government body, and a university.
  • Victims were located in Portuguese- and Spanish-speaking countries across Europe, Africa, and Latin America.
  • The attackers used a vulnerable signed driver, K7RKScan, to disable security software before deploying ransomware.
  • They also abused Visual Studio Code’s tunneling feature for covert remote access and used SYSVOL to spread ransomware across many hosts.
  • Recent activity showed broad domain-wide deployment, with AV/EDR killer tooling reaching at least 40 hosts and Warlock appearing on at least 33 hosts.

MITRE Techniques

  • [T1190 ] Exploit Public-Facing Application – Gained initial access by exploiting Microsoft SharePoint Server flaws and the ToolShell chain (‘exploiting zero-day vulnerabilities in Microsoft SharePoint Server’ and ‘exploitation of vulnerabilities in Microsoft SharePoint Server deployments’).
  • [T1505.003 ] Web Shell – Dropped a webshell into the SharePoint LAYOUTS directory to maintain access and execute code (‘the group drops a webshell into the SharePoint LAYOUTS directory’).
  • [T1552.001 ] Credentials In Files – Harvested SharePoint farm ASP.NET machine keys to forge signed payloads (‘harvest the SharePoint farm’s ASP.NET machine keys’).
  • [T1059.001 ] PowerShell – Used PowerShell to write the webshell, run recon commands, and invoke web requests (‘WriteAllBytes’, ‘net user /domain and whoami’, and ‘Invoke-WebRequest’).
  • [T1027 ] Obfuscated Files or Information – Used base64-encoded PowerShell and encoded payloads to hide malicious content (‘base64-encoded PowerShell command’ and ”).
  • [T1218.011 ] Signed Binary Proxy Execution: Rundll32? Actually not used.
  • [T1574.002 ] DLL Side-Loading – Loaded malicious code via legitimate executables such as doexe.exe, ssvagent.exe, and logger.exe (‘The group uses DLL sideloading’).
  • [T1105 ] Ingress Tool Transfer – Downloaded follow-on payloads from catbox[.]moe and wasabisys[.]com and used msiexec to fetch packages (‘downloads follow-on payloads from legitimate cloud file-sharing and storage services’ and ‘msiexec against two separate URLs’).
  • [T1562.001 ] Impair Defenses – Disabled security software using a vulnerable driver and AV/EDR killer tooling (‘disable security software’ and ‘AV/EDR-killing tool’).
  • [T1068 ] Exploitation for Privilege Escalation – Abused a vulnerable signed driver to terminate protected security processes at kernel level (‘terminate protected security processes at the kernel level’).
  • [T1219 ] Remote Access Software – Abused Visual Studio Code tunnel features for covert remote access (‘code-insiders.exe tunnel service install’).
  • [T1021 ] Remote Services – Used remote access and lateral movement tooling across the domain, including NetExec and administrative shares (‘remote command execution’ and ‘moving across the wider domain’).
  • [T1069.002 ] Permission Groups Discovery: Domain Groups – Enumerated domain trust relationships with nltest /domain_trusts (‘enumerate the victim’s Active Directory domain trust relationships’).
  • [T1136.002 ] Create Account: Domain Account – Added the SPSEPRDSetup account to local Administrators on multiple hosts (‘added a domain account named SPSEPRDSetup to the local Administrators group’).
  • [T1098 ] Account Manipulation – Modified local administrators group membership to expand access (‘added … to the local Administrators group’).
  • [T1036 ] Masquerading – Chose an account name resembling legitimate SharePoint setup accounts (‘attempt to masquerading’).
  • [T1489 ] Service Stop – Disabled or stopped security processes before ransomware deployment (‘disable security software before deploying ransomware’).
  • [T1078 ] Valid Accounts – Used domain accounts and legitimate credentials/traffic to blend in (‘net use … /user’ and traffic that typically originates from developer or administrator workstations).
  • [T1083 ] File and Directory Discovery – Performed reconnaissance and enumerated system/domain information (‘net user /domain’, ‘whoami’, and ‘nltest /domain_trusts’).
  • [T1210 ] Exploitation of Remote Services – Spread and executed payloads via SYSVOL replication and domain controller distribution (‘SYSVOL… automatically replicated to every domain controller’).
  • [T1055 ] Process Injection – Not explicitly stated.

Indicators of Compromise

  • [File hashes ] Warlock and related malicious binaries – 116ca4e88a1bcebb6c0da7fb431c8eca7b8ef3f9767194820c56091972ccac2c, 155fb1cbdaea12c83ba92d18c88cf38bbc42bb684f913ca0bc26fcf115426a55, and other 10+ hashes
  • [File names ] Payloads and tooling observed on hosts – run.exe, rune.exe, a.exe, and other named executables such as ssvagent.exe and logger.exe
  • [File names ] Malicious and suspicious DLLs used for sideloading – doexeloc.dll, gsdll64.dll.tmp, and other 8+ DLL-related artifacts
  • [Domain / URL ] Follow-on delivery and tunneling infrastructure – litter[.]catbox[.]moe, xn8xyt-drop.s3[.]wasabisys[.]com, and other hosting endpoints such as catbox[.]moe and wasabisys[.]com
  • [File path / directory ] SharePoint and SYSVOL staging locations – CSIDL_PROGRAM_FILES_COMMONmicrosoft sharedweb server extensions14templatelayoutslayout2sp.aspx, CSIDL_WINDOWSSYSVOLdomainscriptsrun
  • [Command line / tool names ] Reconnaissance and lateral movement commands – net user /domain, whoami, nltest /domain_trusts, and nxc.exe
  • [Driver name ] Vulnerable driver abused for defense evasion – K7RKScan


Read more: https://www.security.com/threat-intelligence/warlock-ransomware-critical-infrastructure