Longlegs, a China-nexus threat actor tracked by Symantec, is using Microsoft SharePoint vulnerabilities and the Warlock ransomware to compromise organizations across multiple regions. The campaign has hit critical infrastructure, government, and university victims, while also abusing a vulnerable driver, Visual Studio Code tunneling, and SYSVOL to disable defenses and deploy payloads at scale. #Warlock #Longlegs #Storm2603 #ToolShell #K7RKScan #SharePoint #SYSVOL
Keypoints
- Longlegs, also known as Storm-2603, is the China-nexus group Symantec links to the Warlock ransomware operation.
- The group initially gained prominence by exploiting Microsoft SharePoint âToolShellâ vulnerabilities for initial access.
- In the past two months, at least four organizations were targeted, including a water utility, a telecommunications provider, a regional government body, and a university.
- Victims were located in Portuguese- and Spanish-speaking countries across Europe, Africa, and Latin America.
- The attackers used a vulnerable signed driver, K7RKScan, to disable security software before deploying ransomware.
- They also abused Visual Studio Codeâs tunneling feature for covert remote access and used SYSVOL to spread ransomware across many hosts.
- Recent activity showed broad domain-wide deployment, with AV/EDR killer tooling reaching at least 40 hosts and Warlock appearing on at least 33 hosts.
MITRE Techniques
- [T1190 ] Exploit Public-Facing Application â Gained initial access by exploiting Microsoft SharePoint Server flaws and the ToolShell chain (âexploiting zero-day vulnerabilities in Microsoft SharePoint Serverâ and âexploitation of vulnerabilities in Microsoft SharePoint Server deploymentsâ).
- [T1505.003 ] Web Shell â Dropped a webshell into the SharePoint LAYOUTS directory to maintain access and execute code (âthe group drops a webshell into the SharePoint LAYOUTS directoryâ).
- [T1552.001 ] Credentials In Files â Harvested SharePoint farm ASP.NET machine keys to forge signed payloads (âharvest the SharePoint farmâs ASP.NET machine keysâ).
- [T1059.001 ] PowerShell â Used PowerShell to write the webshell, run recon commands, and invoke web requests (âWriteAllBytesâ, ânet user /domain and whoamiâ, and âInvoke-WebRequestâ).
- [T1027 ] Obfuscated Files or Information â Used base64-encoded PowerShell and encoded payloads to hide malicious content (âbase64-encoded PowerShell commandâ and â).
- [T1218.011 ] Signed Binary Proxy Execution: Rundll32? Actually not used.
- [T1574.002 ] DLL Side-Loading â Loaded malicious code via legitimate executables such as doexe.exe, ssvagent.exe, and logger.exe (âThe group uses DLL sideloadingâ).
- [T1105 ] Ingress Tool Transfer â Downloaded follow-on payloads from catbox[.]moe and wasabisys[.]com and used msiexec to fetch packages (âdownloads follow-on payloads from legitimate cloud file-sharing and storage servicesâ and âmsiexec against two separate URLsâ).
- [T1562.001 ] Impair Defenses â Disabled security software using a vulnerable driver and AV/EDR killer tooling (âdisable security softwareâ and âAV/EDR-killing toolâ).
- [T1068 ] Exploitation for Privilege Escalation â Abused a vulnerable signed driver to terminate protected security processes at kernel level (âterminate protected security processes at the kernel levelâ).
- [T1219 ] Remote Access Software â Abused Visual Studio Code tunnel features for covert remote access (âcode-insiders.exe tunnel service installâ).
- [T1021 ] Remote Services â Used remote access and lateral movement tooling across the domain, including NetExec and administrative shares (âremote command executionâ and âmoving across the wider domainâ).
- [T1069.002 ] Permission Groups Discovery: Domain Groups â Enumerated domain trust relationships with nltest /domain_trusts (âenumerate the victimâs Active Directory domain trust relationshipsâ).
- [T1136.002 ] Create Account: Domain Account â Added the SPSEPRDSetup account to local Administrators on multiple hosts (âadded a domain account named SPSEPRDSetup to the local Administrators groupâ).
- [T1098 ] Account Manipulation â Modified local administrators group membership to expand access (âadded ⌠to the local Administrators groupâ).
- [T1036 ] Masquerading â Chose an account name resembling legitimate SharePoint setup accounts (âattempt to masqueradingâ).
- [T1489 ] Service Stop â Disabled or stopped security processes before ransomware deployment (âdisable security software before deploying ransomwareâ).
- [T1078 ] Valid Accounts â Used domain accounts and legitimate credentials/traffic to blend in (ânet use ⌠/userâ and traffic that typically originates from developer or administrator workstations).
- [T1083 ] File and Directory Discovery â Performed reconnaissance and enumerated system/domain information (ânet user /domainâ, âwhoamiâ, and ânltest /domain_trustsâ).
- [T1210 ] Exploitation of Remote Services â Spread and executed payloads via SYSVOL replication and domain controller distribution (âSYSVOL⌠automatically replicated to every domain controllerâ).
- [T1055 ] Process Injection â Not explicitly stated.
Indicators of Compromise
- [File hashes ] Warlock and related malicious binaries â 116ca4e88a1bcebb6c0da7fb431c8eca7b8ef3f9767194820c56091972ccac2c, 155fb1cbdaea12c83ba92d18c88cf38bbc42bb684f913ca0bc26fcf115426a55, and other 10+ hashes
- [File names ] Payloads and tooling observed on hosts â run.exe, rune.exe, a.exe, and other named executables such as ssvagent.exe and logger.exe
- [File names ] Malicious and suspicious DLLs used for sideloading â doexeloc.dll, gsdll64.dll.tmp, and other 8+ DLL-related artifacts
- [Domain / URL ] Follow-on delivery and tunneling infrastructure â litter[.]catbox[.]moe, xn8xyt-drop.s3[.]wasabisys[.]com, and other hosting endpoints such as catbox[.]moe and wasabisys[.]com
- [File path / directory ] SharePoint and SYSVOL staging locations â CSIDL_PROGRAM_FILES_COMMONmicrosoft sharedweb server extensions14templatelayoutslayout2sp.aspx, CSIDL_WINDOWSSYSVOLdomainscriptsrun
- [Command line / tool names ] Reconnaissance and lateral movement commands â net user /domain, whoami, nltest /domain_trusts, and nxc.exe
- [Driver name ] Vulnerable driver abused for defense evasion â K7RKScan
Read more: https://www.security.com/threat-intelligence/warlock-ransomware-critical-infrastructure