Symantec said a China-linked group it calls Longlegs, also tracked as Storm-2603, built Warlock ransomware. It says the group attacked at least four organizations in the past two months. BleepingComputer covered the findings on October 2. Two of the victims, a water utility and a telecom provider, run essential services. The others were a university and a regional government body. All were in Portuguese- or Spanish-speaking countries across Europe, Africa and Latin America. In one attack, activity began July 22. The final phase came July 31, when a tool to switch off security software ran on at least 40 hosts within about two hours. Warlock then ran on at least 33.
Symantec said the group gets in through SharePoint servers that organizations run themselves. A planted web page collects the server's machine keys. Those keys let attackers forge validly signed requests and run code. The ransomware sat in SYSVOL, a shared Windows folder copied across a network, so ordinary copying delivered it. Symantec said the driver used to disable security tools in the July attack is unknown. In other attacks, it was K7RKScan, a signed but flawed driver. Symantec said the country focus could be chance or deliberate targeting.
This attack works by using parts of a network that are trusted: keys the server accepts, a signed driver, and Windows' own copying. Symantec said SharePoint servers left unpatched or unmitigated remain open to the ToolShell flaws. Teams running SharePoint should confirm fixes are applied and test whether their security tools survive a driver-based shutdown.