As reported by SecurityAffairs, the threat actor behind Warlock ransomware — tracked by Symantec as Longlegs (also Storm-2603) — continues to exploit the ToolShell chain of SharePoint vulnerabilities more than a year after they were first disclosed. Recent victims include a water utility, a telecom provider, a regional government, and a university, all in Portuguese- and Spanish-speaking countries. The fact that a year-old vulnerability chain remains a reliable initial-access vector against critical infrastructure should set off alarm bells in every SOC managing exposed Microsoft SharePoint servers.
Why This Still Works — and Why That's the Real Problem
The ToolShell vulnerabilities, disclosed in mid-2025, allow attackers to deploy webshells into the SharePoint LAYOUTS directory and steal ASP.NET machine keys. Those keys are then used to craft signed payloads that execute within the SharePoint application context. Microsoft released patches for these flaws months ago, yet Longlegs is still breaching organizations with them. The exploitation chain hasn't evolved — the attack surface has simply remained unmanaged.
This tells us the bottleneck isn't attacker sophistication. It's defender patch latency. Critical infrastructure organizations — particularly smaller water utilities and regional government bodies — often lack dedicated patching cycles for infrastructure-facing collaboration platforms. SharePoint servers are frequently treated as "set-and-forget" deployments, making them soft targets for any group willing to scan for exposed instances.
Attack Chain Summary
| Stage | Tactic | Technique |
|---|---|---|
| Initial Access | Exploit public-facing app | ToolShell SharePoint vulnerabilities (unpatched) |
| Persistence | Webshell deployment | Webshell placed in SharePoint LAYOUTS directory |
| Credential Access | Key theft | ASP.NET machine key extraction for payload signing |
| Defense Evasion | BYOVD | Signed but vulnerable K7RKScan driver to kill security tools |
| Remote Access | Legitimate tooling abuse | VS Code tunneling installed as a service |
| Payload Delivery | Masquerading | DLL sideloading; downloads via catbox.moe, wasabisys.com |
| Impact | Encryption | Warlock ransomware deployment |
The BYOVD Problem Persists
Longlegs' use of the K7RKScan signed driver to disable endpoint security before deploying ransomware is a well-documented BYOVD (Bring Your Own Vulnerable Driver) technique. This is not unique to Warlock — multiple ransomware and intrusion groups have weaponed legitimately signed drivers from various security vendors over the past several years. The pattern is predictable: the driver is signed and trusted by the OS, so it loads without issue, then the attacker abuses its functionality to turn off protection.
Microsoft's Vulnerable Driver Blocklist is the primary defense here, but it requires enforcement via WDAC or memory integrity settings — neither of which is enabled by default on many server deployments. Organizations running SharePoint on Windows Server without HVCI enabled are leaving this door wide open.
VS Code Tunneling as a Blind Spot
One of the more notable tradecraft choices in this campaign is the installation of VS Code's remote tunneling feature as a Windows service. This creates a persistent, encrypted reverse shell that masquerades as legitimate developer activity. Most endpoint detection tools won't flag it because VS Code is a trusted Microsoft-signed binary. Security teams that haven't instrumented detection for tunneling-capable developer tools are missing a growing attack surface that threat actors across multiple clusters now favor.
Shield53 Recommendations
code.exe or code-tunnel.exe running as a Windows service or spawning from non-standard directories. Alert on VS Code tunnel processes initiated by service accounts or SYSTEM context.catbox.moe and wasabisys.com from server infrastructure. While these are legitimate services, their use from production SharePoint servers is highly suspicious..aspx file added outside of a controlled deployment should trigger an immediate investigation.The story here isn't that Longlegs is sophisticated — it's that critical infrastructure is still running unpatched servers more than a year after a headline-grabbing vulnerability disclosure. Until patching becomes a board-level priority for utilities and municipal governments, this pattern will repeat with every new toolset.