The rapid convergence of physical utilities and digital control systems has created a sprawling attack surface that state-linked actors are now exploiting with alarming precision and destructive intent. Recently, a China-nexus threat actor known as Longlegs or Storm-2603 has pivoted its focus toward essential service providers, threatening the stability of water utilities and telecommunications networks across the globe. This adversary specializes in compromising high-value targets within Portuguese- and Spanish-speaking regions, utilizing a blend of advanced exploitation techniques and localized intelligence gathering. By leveraging the Warlock ransomware, these operators aim not just for financial gain but for significant operational disruption within the public sector. The group’s ability to infiltrate critical environments through vulnerable enterprise software like Microsoft SharePoint demonstrates a sophisticated understanding of corporate network architecture. This shift marks a concerning era where the security of basic societal functions depends entirely on the integrity of internal servers and their defense.
Vulnerability Exploitation and Initial Access
Technical Foundations: The SharePoint Exploit Chain
The primary entry point for these coordinated attacks involves the exploitation of the SharePoint ToolShell exploit chain, which allows attackers to bypass security controls and gain unauthorized access to on-premises servers. While initial vulnerabilities like CVE-2025-49704 and CVE-2025-49706 were addressed with previous security updates, the threat actors have quickly adapted by utilizing newer bypasses categorized under CVE-2025-53770 and CVE-2025-53771. These flaws are particularly dangerous because they facilitate Remote Code Execution, giving the adversary the ability to run arbitrary commands within the context of the SharePoint application.
This persistent focus on SharePoint highlights a strategic effort to target legacy infrastructure that remains vital to many public-sector organizations despite the availability of cloud-based alternatives. By focusing on supported on-premises editions, the Longlegs group ensures a high success rate against organizations that may have delayed their migration to more modern, secure environments. The ability to expose sensitive internal configurations through these vulnerabilities provides the attackers with a comprehensive map of the target’s digital footprint before they even begin their lateral movement phase, making the initial breach a critical turning point for the entire network.
Operational Tactics: Persistence and Concealment
To maintain a long-term presence within a compromised network, the attackers deploy ASPX webshells within the LAYOUTS directory, which are designed to hijack the server’s legitimate application pool processes. These webshells serve as a beachhead, allowing the threat actors to extract machine keys and forge signed payloads that bypass traditional authentication mechanisms. By embedding their tools within the existing directory structure of a trusted application, the group ensures that their malicious activities remain hidden from casual observation and standard file integrity monitoring systems that might not be configured to scan every legitimate application subdirectory.
The group further evades detection by utilizing DLL side-loading and hosting their malicious installers on reputable public cloud services like Catbox and Wasabi to blend in with routine network traffic. This tactic ensures that the traffic generated during the payload retrieval phase mimics common administrative or cloud-syncing activity, often bypassing perimeter security filters that do not scrutinize data coming from established, legitimate domains. Furthermore, the establishment of covert communication bridges through the abuse of the Tunnel function in Visual Studio Code allows the unauthorized access to appear as standard developer behavior, effectively neutralizing many common behavioral alerts.
Defensive Evasion and Domain Infection
Tactical Execution: Neutralizing Defenses via Kernel Space
A defining characteristic of the Warlock campaign is the aggressive neutralization of defensive software before the final ransomware deployment occurs across the network. The actors employ a Bring Your Own Vulnerable Driver technique, using a signed but flawed driver to terminate security processes directly from the kernel space where antivirus software has little control. This method effectively blinds Endpoint Detection and Response tools, allowing the attackers to disable protections across dozens of hosts within a very short timeframe. By exploiting the missing authorization in the driver’s IOCTL handler, the group moves through the environment without triggering the usual security warnings.
This kernel-level interference is particularly effective because it targets the very foundation of modern security stacks, making it impossible for defenders to respond once the driver is active. The speed at which the Longlegs group can neutralize an entire department’s defenses demonstrates a high level of operational maturity and preparation. Once the security agents are disabled, the attackers can execute follow-on commands and deploy their ransomware payloads with total impunity, knowing that no alerts will be generated. This phase of the attack is a prerequisite for the mass distribution that follows, ensuring that the encryption process is not interrupted by automated quarantine or block actions.
Strategic Distribution: Weaponizing the SYSVOL Share
Once the environment is rendered defenseless, the attackers utilize the organization’s own trust architecture to distribute the ransomware to every connected machine. By placing malicious binaries and the ransom note within the Active Directory SYSVOL share, they leverage built-in Distributed File System Replication to automatically spread the infection. This ingenious use of administrative features ensures a rapid, domain-wide paralysis that is incredibly difficult to contain once the replication process begins. Because SYSVOL is a legitimate part of the domain’s functionality, most internal monitoring tools do not flag the addition of new files as a high-risk event.
The replication of the ransomware to all domain controllers ensures that even if one segment of the network is isolated, the infection continues to propagate through the central identity infrastructure. This weaponization of the SYSVOL share turns the primary tool of network administration into a primary vector for total compromise, highlighting a major structural vulnerability in how many organizations manage their domain resources. By the time the ransomware is executed, the entire organization is already saturated with the malicious files, making the recovery process significantly more complex as the infection is deeply embedded in the core of the network’s directory services.
Strategic Implications and Risk Mitigation
Geopolitical Motives: Regional Disruption and Intelligence
The geographic and sectoral focus of these campaigns suggests that the underlying motivation extends beyond simple financial gain or the collection of a traditional ransom. The targeting of essential services in specific Spanish- and Portuguese-speaking language zones indicates a dual-purpose mission that likely involves both regional disruption and the gathering of strategic intelligence. By holding critical infrastructure like water utilities hostage, the Longlegs group exerts significant pressure on regional governments, potentially serving the broader geopolitical interests of their nexus. This approach moves ransomware from a criminal enterprise into the realm of state-level coercive activity.
This strategic alignment means that organizations must view these attacks as part of a larger pattern of persistent engagement rather than isolated criminal events. The speed at which these actors exploit known vulnerabilities underscores the need for organizations to treat software security as a critical priority rather than a routine maintenance task. When critical infrastructure is at risk, the impact of a breach is measured in public safety and national security rather than just financial loss. Understanding the adversary’s broader goals helps defenders better anticipate their movements and prioritize the protection of the most sensitive and essential segments of their internal infrastructure.
Actionable Resilience: Hardening Infrastructure and Future Steps
Securing an environment against this sophisticated threat required a multifaceted approach that went beyond basic patching and involved a fundamental shift in defensive posture. Proactive hunting for ASPX webshells in the LAYOUTS directory and the mandatory rotation of ASP.NET and IIS machine keys became standard practice for those looking to prevent re-entry. Organizations successfully mitigated these risks by enabling the Antimalware Scan Interface in Full Mode and deploying EDR solutions that were specifically configured to detect the unauthorized use of vulnerable drivers. Restricting SharePoint’s exposure to the public internet through authenticated proxies also served as a vital barrier.
Hardening the network also involved strict auditing of the SYSVOL share and the monitoring of administrative tools like Visual Studio Code for unauthorized remote tunnels. Moving forward, the focus shifted toward asset discovery and the rapid containment of any server that showed signs of initial exploitation. By implementing these rigorous defensive measures, critical infrastructure providers were able to close the gap that Longlegs exploited, ensuring that legacy systems no longer acted as an easy entry point for state-linked ransomware campaigns. The lessons learned from the Warlock intrusions emphasized that visibility into the kernel and the integrity of the domain architecture are the primary pillars of modern resilience.
