The breach isn’t the problem. The spread is. →Free Assessment

Executive Summary

The China-linked Warlock ransomware group (also tracked as Longlegs and Storm-2603) conducted a sophisticated attack campaign targeting critical infrastructure including water utilities, telecom providers, regional governments, and universities across Portuguese and Spanish-speaking regions. The group exploited the ToolShell vulnerability chain (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771) in Microsoft SharePoint deployments to gain initial access, then deployed EDR-killing tools via BYOVD techniques affecting up to 40 hosts within two hours before executing ransomware on 33 systems.

This incident highlights the growing convergence of state-sponsored APT tactics with ransomware operations, demonstrating how sophisticated threat actors are increasingly targeting critical infrastructure through supply chain vulnerabilities and leveraging legitimate tools like Visual Studio Code tunneling for persistence and remote access.

Why This Matters Now

Critical infrastructure faces escalating threats as ransomware groups adopt nation-state level tactics, exploiting unpatched SharePoint vulnerabilities that remain viable attack vectors over a year after disclosure, requiring immediate attention to hybrid cloud security and zero-trust segmentation.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The attacks combined state-sponsored APT techniques with ransomware deployment, using zero-day SharePoint exploits, EDR-killing tools via BYOVD methods, and legitimate tools like Visual Studio Code for persistence.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would likely have significantly constrained Warlock ransomware's ability to rapidly spread across 40+ hosts and execute domain-wide encryption. The segmented architecture could have reduced blast radius by limiting lateral movement pathways and controlling east-west traffic flows within the compromised infrastructure networks.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: While initial SharePoint exploitation may still occur, CNSF fabric visibility would likely have enabled faster detection of anomalous web shell activity and constrained the attacker's ability to establish deeper persistence across multiple infrastructure segments.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Zero trust segmentation would likely have limited the scope of Active Directory enumeration activities and constrained credential spraying effectiveness by restricting access pathways between network segments and reducing the attack surface for privilege escalation.

Lateral Movement

Control: East-West Traffic Security

Mitigation: East-west traffic controls would likely have significantly constrained the rapid lateral movement by enforcing micro-segmentation policies that limit host-to-host communication pathways, potentially reducing the scope from 40+ compromised systems to isolated network segments.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Multicloud visibility controls would likely have detected the unauthorized VS Code tunneling service installation and constrained command and control communications by identifying anomalous outbound connection patterns from critical infrastructure systems.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Egress security controls would likely have constrained data exfiltration activities by monitoring and limiting outbound data flows from critical infrastructure systems, reducing the volume of sensitive information that could be transferred to external command and control infrastructure.

Impact (Mitigations)

Despite ransomware execution on compromised systems, the segmented architecture would likely have contained encryption impact to isolated network segments rather than allowing unrestricted domain-wide propagation, potentially limiting affected assets in water utility, telecom, and government infrastructure.

Impact at a Glance

Affected Business Functions

  • Water Treatment Operations
  • Telecommunications Infrastructure
  • Public Services
  • Educational Systems
Operational Disruption

Estimated downtime: 18 days

Financial Impact

Estimated loss: $2,500,000

Data Exposure

Critical infrastructure operational data, customer telecommunications records, university student and faculty information, and municipal government citizen data across Portuguese and Spanish speaking regions

Recommended Actions

  • • Implement Zero Trust Segmentation with identity-based policies to prevent rapid lateral movement across 40+ hosts within hours
  • • Deploy Egress Security & Policy Enforcement to detect and block unauthorized data exfiltration and C2 tunneling activities like VS Code remote access
  • • Enable East-West Traffic Security controls to monitor and restrict internal network flows during Active Directory enumeration and credential spraying attempts
  • • Establish Multicloud Visibility & Control to detect anomalous automation patterns, suspicious tool deployment, and EDR disabling activities in real-time
  • • Configure Threat Detection & Anomaly Response capabilities to identify covert remote access tools and baseline deviations during reconnaissance phases

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image