Your enterprise is running Microsoft SharePoint on-premises. A junior employee with standard Site Member access opens a malformed document. Within hours, every domain controller on your network is encrypting files simultaneously — because a Chinese state-linked group called Storm-2603 weaponised Active Directory’s own replication engine to spread ransomware. This is not a theoretical scenario. It is happening right now, and the targets include water utilities, telecom operators, and government bodies.

Key Takeaways

  • Warlock ransomware, operated by Chinese APT Storm-2603 (aka Longlegs, ChamelGang), is actively hitting critical infrastructure — water utilities, telecom providers, regional governments — across Spanish- and Portuguese-speaking nations in Europe, Africa, and Latin America.
  • Initial access rides CVE-2026-45659 (CVSS 8.8), a Microsoft SharePoint deserialization flaw patched in May 2026 but still found unpatched on hundreds of internet-exposed servers.
  • The group uses BYOVD (Bring Your Own Vulnerable Driver) via the K7RKScan driver (CVE-2025-1055) to blind endpoint security before encryption begins.
  • Ransomware is staged in SYSVOL and distributed to every domain controller via standard AD replication — no remote execution tool needed, and no noisy lateral movement to trigger alerts.
  • Patching SharePoint is necessary but not sufficient. Zero-trust segmentation of internal AD replication paths and privileged-access workstations (PAWs) are the structural defences that stop this class of attack.

Who Is Storm-2603 (Longlegs)?

Storm-2603 is a China-nexus advanced persistent threat group that Symantec tracks under the moniker Longlegs. The group has previously operated under the aliases CL-CRI-1040, CamoFei, and ChamelGang — a lineage that signals long-running, state-tolerated cybercriminal operations with a side of espionage.

Warlock, the ransomware family this group deploys, emerged in June 2025 when Storm-2603 began exploiting the infamous ToolShell exploit chain — a set of four zero-day flaws in on-premises SharePoint Server (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, CVE-2025-53771) that Microsoft rushed to patch. The group also deploys LockBit in some intrusions, pairing it with a custom C2 framework labelled AK47C2, suggesting a dual-purpose operation: financial extortion and strategic data collection.

What makes Storm-2603 particularly dangerous is its discipline in blending in. Rather than noisy remote execution tools, it abuses built-in Windows and enterprise features — a hallmark of sophisticated Chinese APT operations that have repeatedly frustrated detection-first security strategies across Asia and Europe.

The Attack Chain: From a SharePoint Login to Encrypted Domain Controllers

SecurityWeek’s reporting and The Record’s analysis of the latest Storm-2603 campaign reveal an attack chain that is elegant in its abuse of enterprise trust:

Stage Technique Why It Works
1. Initial Access Exploit CVE-2026-45659 via a low-privilege SharePoint account Site Member is the default access level for most employees; no admin needed
2. Persistence VS Code Remote Tunneling (living-off-the-land) Legitimate developer tool; most firewalls and DLP tools whitelist it
3. Defence Evasion Load K7RKScan (CVE-2025-1055) via BYOVD to terminate EDR/AV Signed kernel-mode driver; bypasses most endpoint controls
4. DLL Sideloading Abuse DLL search-order to inject Warlock loader Runs under a trusted process; evades application whitelisting
5. Lateral Spread Stage payload in SYSVOL; let AD replication carry it to all DCs No PsExec, no SMB spray — AD itself distributes the ransomware
6. Encryption Deploy Warlock (or LockBit) simultaneously across all domain-joined hosts Coordinated execution before defenders can respond

The SYSVOL manoeuvre is particularly alarming. SYSVOL is a shared folder that every domain controller replicates automatically as part of normal AD operations. By placing the ransomware executable there, Storm-2603 achieves network-wide deployment without touching a single remote execution protocol — the very protocols that most lateral-movement detection rules are written to flag.

CVE-2026-45659: The SharePoint Flaw at the Root of This Campaign

CVE-2026-45659 is a deserialization vulnerability in Microsoft SharePoint Server. SharePoint fails to properly validate untrusted data during deserialization, allowing an authenticated attacker — with nothing more than standard Site Member permissions — to execute arbitrary code on the server without user interaction.

  • CVSS Score: 8.8 (High)
  • Affected versions: SharePoint Server Subscription Edition, SharePoint Server 2019, SharePoint Enterprise Server 2016
  • Patch released: May 2026 (Microsoft Security Updates; note: Microsoft inadvertently omitted the CVE from its May release notes, correcting the advisory only on May 27)
  • Added to CISA KEV Catalog: July 2, 2026 — remediation deadline was July 4, 2026 for all US federal agencies
  • Exposure: As of October 2026, Shadowserver tracks over 8,500 on-premises SharePoint servers publicly accessible on the internet; more than 200 remain unpatched against CVE-2026-45659

The CISA deadline has passed. Any organisation still running an unpatched on-premises SharePoint in October 2026 is, statistically, already a target — and potentially already compromised. Storm-2603’s campaign reported by ReliaQuest confirms active, opportunistic scanning and exploitation of these residual unpatched servers.

Why Critical Infrastructure? The Chinese APT Calculus

The choice of water utilities, telecom providers, and regional governments is not random. This targeting mirrors a broader pattern seen across Chinese state-linked groups — from Volt Typhoon’s long-dwell campaigns in US critical infrastructure to the Zyxel switch exploitation campaign attributed to Chinese threat actors that compromised nearly a thousand network devices.

Critical infrastructure organisations typically share several characteristics that make them attractive targets: they run legacy on-premises software (SharePoint 2016/2019 rather than SharePoint Online), they operate 24/7 with limited change-management windows for patching, and their operational disruption carries outsized geopolitical and economic consequences — exactly the leverage a state-aligned group wants in its back pocket.

The Spanish- and Portuguese-speaking geography of the current Warlock campaign — spanning Europe, Africa, and Latin America — also fits a Chinese strategic interest in countries that hold Belt and Road infrastructure investments, commodity supply chains, and diplomatic relationships. Ransomware here is as much about intelligence collection as financial extortion.

What You Should Do Right Now: Sanjay Seth’s Defence Playbook

A purely patch-and-pray response is insufficient for this threat. Here is the layered defence posture I recommend to my NOC/SOC clients and enterprise customers:

Immediate (within 48 hours):

  1. Patch SharePoint immediately. Apply the May 2026 Cumulative Update (or June/July if available) covering CVE-2026-45659. Verify the patch applied correctly — Microsoft’s release-notes omission means some automated patching tools may have missed it. Cross-check your installed build against the CISA KEV remediation guidance.
  2. Audit exposed SharePoint instances. If your SharePoint is not behind a VPN or zero-trust access proxy, take it off the public internet today. There is no business case that outweighs the risk in October 2026.
  3. Hunt for K7RKScan (K7RKScan.sys) in your environment. Its presence is a near-certain indicator of Storm-2603 activity. Also audit for VS Code Server processes running on non-developer machines — a sure sign of LotL persistence.

Short-Term (within 2 weeks):

  1. Restrict SYSVOL write access. Only domain controllers and authorised GPO management workstations should be able to write to SYSVOL. Audit and lock down these permissions aggressively. Enable File System auditing on SYSVOL and pipe alerts to your SIEM.
  2. Implement Privileged Access Workstations (PAWs). Attackers reached AD replication through a compromised application server. Zero-trust segmentation — isolating domain controller management traffic from general application traffic — is the structural control that breaks this kill chain.
  3. Block vulnerable drivers. Add K7RKScan (CVE-2025-1055) to your kernel driver blocklist via Windows Defender Application Control (WDAC) or your EDR’s block-by-hash feature. Microsoft’s Recommended Driver Block Rules should be reviewed and deployed.

Strategic (1–3 months):

  1. Migrate SharePoint to SharePoint Online (M365). The on-premises attack surface disappears. Microsoft manages the patching cycle. This single architectural decision removes the initial access vector entirely for most organisations.
  2. Deploy a zero-trust network architecture. Mandate identity verification before any internal resource — including SharePoint — is accessible. Micro-segmentation prevents the lateral movement that transforms a single server compromise into a domain-wide catastrophe. See our guide on building resilient, segmented network architectures for distributed Indian sites.
  3. Run a tabletop exercise against a Storm-2603-style playbook. Walk your SOC team through: SharePoint exploit → BYOVD → SYSVOL staging → AD replication. Test whether your existing controls would detect and contain each stage.

A Note for Indian Enterprises

India has seen a sharp uptick in Chinese APT activity in 2026, from Pakistan-linked APT36’s RapidRust campaign targeting Indian defence and government to the broader Chinese state-sponsored operations targeting critical infrastructure globally. Storm-2603’s current campaign is geographically focused on Spanish- and Portuguese-speaking nations, but its techniques — SharePoint exploitation, BYOVD, AD abuse — are entirely applicable to Indian on-premises environments.

Large Indian enterprises in manufacturing, telecommunications, and government have significant SharePoint 2016/2019 footprints, often running behind perimeter firewalls with limited internal micro-segmentation. If that describes your environment, the attack chain described above is tailor-made for it. Treat this campaign as a rehearsal warning, not a distant threat.

Frequently Asked Questions

Is SharePoint Online (Microsoft 365) vulnerable to CVE-2026-45659?

No. CVE-2026-45659 only affects on-premises SharePoint Server (Subscription Edition, 2019, and 2016). SharePoint Online is a cloud-managed service patched by Microsoft; tenants do not need to take any action. This is one of the strongest practical arguments for migrating off on-premises SharePoint.

We patched SharePoint in May 2026. Are we safe?

Patching CVE-2026-45659 removes the primary initial access vector for the current campaign. However, Storm-2603 also retains the older ToolShell CVEs in its arsenal (CVE-2025-49704/49706/53770/53771) for any unpatched 2025 windows. More critically, if your organisation was compromised before patching, the attacker may already have established VS Code tunnel persistence or placed a loader in SYSVOL. Patching stops new intrusions; it does not evict an attacker already inside. Run a compromise assessment.

What is BYOVD and why can’t our antivirus stop it?

BYOVD (Bring Your Own Vulnerable Driver) is a technique where an attacker loads a legitimate, digitally signed kernel driver that contains a known vulnerability. Because the driver is signed, Windows loads it without complaint. The attacker then exploits the driver’s vulnerability to run code at kernel level — the same privilege level as your EDR/AV. From kernel level, they can terminate any security process. The defence is to proactively blocklist known-vulnerable drivers using WDAC or your EDR’s kernel driver controls, before an attacker gets the chance to load them.

Does my FortiGate firewall protect against this attack?

FortiGate’s IPS and Application Control signatures can detect and block known exploitation patterns for SharePoint CVEs, including the ToolShell chain. Ensure your IPS signatures are up to date and that FortiGuard subscriptions are active. FortiGate’s SSL inspection is also critical if your SharePoint traffic traverses a gateway — without it, encrypted exploit traffic is invisible to the IPS engine. That said, FortiGate sits on the network perimeter; it cannot prevent a BYOVD attack or SYSVOL abuse that is already executing on an internal server. Defence-in-depth is non-negotiable.


Is your SharePoint patched? Is your SYSVOL locked down? Do you know which drivers are running at kernel level in your environment? If you’re uncertain about any of these questions, that uncertainty is itself a finding. Storm-2603 is patient, well-resourced, and actively scanning. The time to find the gaps is before they do.

Book a Security Assessment with Sanjay Seth →