Rewterz

UAT-11587 Conducts China-Nexus Cyber Espionage Campaign Across Asia – Active IOCs

October 1, 2026

Warlock Ransomware Operations Linked to Storm-2603 SharePoint Exploitation – Active IOCs

Severity

High

Analysis Summary

The Warlock ransomware group continues to target Microsoft SharePoint servers, with recent attacks affecting critical infrastructure, government, telecommunications, water utilities, and education organizations across Portuguese- and Spanish-speaking countries. The group is believed to be operated by the China-based threat actor tracked as Longlegs and Storm-2603, which has also been associated with campaigns including CL-CRI-1040, CamoFei, and ChamelGang.

Storm-2603 has repeatedly exploited SharePoint vulnerabilities, including the ToolShell flaws that were abused as zero-days by Chinese state-sponsored groups before public disclosure. More than 400 SharePoint servers were compromised during the resulting wave of attacks. By October 2025, researchers had identified multiple Warlock ransomware incidents exploiting ToolShell, with victims including a Middle Eastern telecommunications company, government organizations in Africa and South America, and a US university.

Recent reporting from a security firm indicates that Storm-2603 continues to exploit SharePoint vulnerabilities as an initial access vector. In addition to ToolShell, the group may have leveraged several 2026 vulnerabilities, including CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, CVE-2026-58644, CVE-2026-50522, and CVE-2026-55040.

The attack chain typically involves exploiting SharePoint flaws, deploying webshells, stealing ASP.NET machine keys, and deploying signed payloads for remote code execution. The threat actor also uses DLL sideloading, legitimate file-sharing services, vulnerable drivers to disable security tools, and legitimate Windows utilities for reconnaissance and command execution.

Security researchers have observed Storm-2603 abusing Visual Studio Code tunnels to establish covert remote access while blending with legitimate developer or administrator traffic. The group has also staged Warlock ransomware within the domain SYSVOL share, enabling the payload to replicate across domain controllers and facilitating large-scale ransomware execution.

In one recent intrusion, security tools were disabled on at least 40 systems before Warlock ransomware was executed on at least 33. The continued activity demonstrates that unpatched or inadequately protected SharePoint deployments remain a significant initial access risk.

Impact

  • Data Encryption
  • Lateral Movement
  • Unauthorized Access
  • Remote Code Execution

Indicators of Compromise

Domain Name

  • litter.catbox.moe

MD5

  • 80961850786d6531f075b8a6f9a756ad
  • 236d499b4aca73da7865947cae8b8340
  • dc58b4b22b45039a179eedec9ed8148b

SHA-256

  • 206f27ae820783b7755bca89f83a0fe096dbb510018dd65b63fc80bd20c03261
  • ae9f7fce57c7b928e659dccf0e00fa79cd9cd61a106f18d4e03f92dc3a03c295
  • c46825fcc0d1bf7a8b192facb176d6bf916c9dccfd6fa994be691e3b0e585f4e

SHA1

  • b0b912a3fd1c05d72080848ec4c92880004021a1
  • 98c1591059a3454be9bdadf33e4f59eb43328a35
  • 68842ac4252aa0b7b04276dbed3503f95f42ae1f

Remediation

  • Apply the latest security patches and mitigations for all affected SharePoint vulnerabilities, including ToolShell and relevant 2026 CVEs.
  • Restrict SharePoint exposure to the internet where external access is not required.
  • Monitor SharePoint servers for suspicious webshells, unauthorized file modifications, and abnormal process execution.
  • Rotate ASP.NET machine keys following suspected or confirmed SharePoint compromise.
  • Monitor and secure SYSVOL shares to prevent unauthorized payload staging and execution.
  • Deploy and maintain endpoint protection capable of detecting ransomware and driver-based security-tool tampering.
  • Monitor for DLL sideloading and execution of unsigned or suspicious binaries.
  • Restrict unauthorized use of Visual Studio Code tunnels and other remote-access mechanisms.
  • Monitor legitimate file-sharing and cloud-storage services for suspicious payload downloads.
  • Implement application allowlisting to prevent unauthorized executables and scripts from running.
  • Enable centralized logging and SIEM monitoring for SharePoint, Active Directory, endpoint, and network activity.
  • Apply least-privilege access controls to SharePoint, administrator accounts, and domain resources.
  • Segment critical infrastructure and sensitive servers to limit lateral movement.
  • Maintain offline or immutable backups and regularly test restoration procedures.
  • Conduct threat hunting for known Storm-2603/Longlegs indicators, webshell activity, and ransomware behaviors.

Reading this advisory was a good start.

Make it a habit.

Rewterz publishes threat advisories ahead of mainstream cybersecurity media, informed by an AI-Native Autonomous SOC that sees regional threat actor activity in real time. Subscribe to receive each new advisory as it publishes, plus a monthly Middle East threat landscape brief drawn from our own SOC telemetry. For teams evaluating their detection coverage, a 30-minute consultation with a senior analyst is also available, at your pace, when you're ready.