As reported by SecurityAffairs, the threat actor behind Warlock ransomware — tracked by Symantec as Longlegs (also Storm-2603) — continues to exploit the ToolShell chain of SharePoint vulnerabilities more than a year after they were first disclosed. Recent victims include a water utility, a telecom provider, a regional government, and a university, all in Portuguese- and Spanish-speaking countries. The fact that a year-old vulnerability chain remains a reliable initial-access vector against critical infrastructure should set off alarm bells in every SOC managing exposed Microsoft SharePoint servers.

Ransomware Alert: As reported by SecurityAffairs, the threat actor behind Warlock ransomware — tracked by Symantec as Longlegs (also Storm-2603) — continues to exploit the ToolShell chain of SharePoint vulnerabilities more than a year after they were first disclosed.

Why This Still Works — and Why That's the Real Problem

The ToolShell vulnerabilities, disclosed in mid-2025, allow attackers to deploy webshells into the SharePoint LAYOUTS directory and steal ASP.NET machine keys. Those keys are then used to craft signed payloads that execute within the SharePoint application context. Microsoft released patches for these flaws months ago, yet Longlegs is still breaching organizations with them. The exploitation chain hasn't evolved — the attack surface has simply remained unmanaged.

This tells us the bottleneck isn't attacker sophistication. It's defender patch latency. Critical infrastructure organizations — particularly smaller water utilities and regional government bodies — often lack dedicated patching cycles for infrastructure-facing collaboration platforms. SharePoint servers are frequently treated as "set-and-forget" deployments, making them soft targets for any group willing to scan for exposed instances.

Attack Chain Summary

StageTacticTechnique
Initial AccessExploit public-facing appToolShell SharePoint vulnerabilities (unpatched)
PersistenceWebshell deploymentWebshell placed in SharePoint LAYOUTS directory
Credential AccessKey theftASP.NET machine key extraction for payload signing
Defense EvasionBYOVDSigned but vulnerable K7RKScan driver to kill security tools
Remote AccessLegitimate tooling abuseVS Code tunneling installed as a service
Payload DeliveryMasqueradingDLL sideloading; downloads via catbox.moe, wasabisys.com
ImpactEncryptionWarlock ransomware deployment

The BYOVD Problem Persists

Longlegs' use of the K7RKScan signed driver to disable endpoint security before deploying ransomware is a well-documented BYOVD (Bring Your Own Vulnerable Driver) technique. This is not unique to Warlock — multiple ransomware and intrusion groups have weaponed legitimately signed drivers from various security vendors over the past several years. The pattern is predictable: the driver is signed and trusted by the OS, so it loads without issue, then the attacker abuses its functionality to turn off protection.

Microsoft's Vulnerable Driver Blocklist is the primary defense here, but it requires enforcement via WDAC or memory integrity settings — neither of which is enabled by default on many server deployments. Organizations running SharePoint on Windows Server without HVCI enabled are leaving this door wide open.

VS Code Tunneling as a Blind Spot

One of the more notable tradecraft choices in this campaign is the installation of VS Code's remote tunneling feature as a Windows service. This creates a persistent, encrypted reverse shell that masquerades as legitimate developer activity. Most endpoint detection tools won't flag it because VS Code is a trusted Microsoft-signed binary. Security teams that haven't instrumented detection for tunneling-capable developer tools are missing a growing attack surface that threat actors across multiple clusters now favor.

Shield53 Recommendations

Shield53 Recommendations
Patch SharePoint immediately. Identify every SharePoint server in your environment — including forgotten on-premises instances — and confirm the ToolShell patches are applied. Prioritize any server reachable from the internet.
Inventory and restrict exposed SharePoint. Any SharePoint server that doesn't require internet-facing access should be moved behind a VPN or zero-trust gateway. Run continuous external attack surface management to catch shadow deployments.
Enable Microsoft's Vulnerable Driver Blocklist. Deploy the blocklist via Group Policy or MEM and enforce Windows Defender Application Control with memory integrity (HVCI) on all Windows Server hosts running SharePoint.
Detect VS Code tunneling abuse. Monitor for code.exe or code-tunnel.exe running as a Windows service or spawning from non-standard directories. Alert on VS Code tunnel processes initiated by service accounts or SYSTEM context.
Block or monitor external hosting domains. Flag traffic to catbox.moe and wasabisys.com from server infrastructure. While these are legitimate services, their use from production SharePoint servers is highly suspicious.
Hunt for webshells in LAYOUTS. Conduct file integrity monitoring on the SharePoint LAYOUTS directory. Any .aspx file added outside of a controlled deployment should trigger an immediate investigation.
Rotate ASP.NET machine keys. If you suspect any exposure, rotate machine keys immediately. Stolen keys allow attackers to forge authentication cookies and execute signed code long after the initial breach.
The story here isn't that Longlegs is sophisticated — it's that critical infrastructure is still running unpatched servers more than a year after a headline-grabbing vulnerability disclosure. Until patching becomes a board-level priority for utilities and municipal governments, this pattern will repeat with every new toolset.