In July 2025, a set of SharePoint zero-days nicknamed ToolShell set off a scramble across universities and government offices. Microsoft shipped fixes that month, teams patched, and most people moved on.
The attackers did not. More than a year later, the ransomware crew that made its name on ToolShell is still finding on-premises SharePoint servers it can break into, and it has been hitting the kinds of organizations RSOC serves.
What happened
Symantec's Threat Hunter Team reported this month that the China-nexus group it calls Longlegs (also tracked as Storm-2603), which develops Warlock ransomware, attacked at least four organizations over the past two months. The victims included a water utility, a telecommunications provider, a regional government body and a university, mostly in Portuguese- and Spanish-speaking countries. The group has previously hit targets in the U.S. as well.
The playbook runs in four steps:
- Get in through SharePoint. The attackers exploit on-premises SharePoint Server vulnerabilities, likely the original ToolShell chain (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770 and CVE-2025-53771) along with newer flaws CISA warned about in July 2026. Symantec has not confirmed which specific bugs were used in each case. SharePoint Online is not affected by ToolShell.
- Steal the keys. A web shell planted in SharePoint's LAYOUTS folder pulls the server's ASP.NET machine keys, which let the attackers forge trusted requests and run code inside SharePoint.
- Blind the defenders. Using a vulnerable but legitimately signed driver, the attackers switched off security software. In one intrusion, protection went dark on at least 40 hosts in about two hours.
- Encrypt. Warlock was then pushed to 33 hosts from the domain's SYSVOL share, the folder every domain-joined computer trusts.
The group also leans on legitimate tools, including the Velociraptor forensics agent and Visual Studio Code tunnels, to blend in. As Symantec put it, the group continues to favor SharePoint-related vulnerabilities for initial access.
Why it matters for Texas institutions
On-premises SharePoint is still common across Texas universities, community colleges and state agencies, often running intranets, document libraries, workflow apps and research collaboration sites that never moved to the cloud. Many were patched in 2025.
The catch is that patching was only half the fix. If a server was compromised before it was patched, the stolen machine keys keep working afterward. A server that looks up to date can still accept forged requests until those keys are rotated. That makes ToolShell-era servers a lingering risk, not a closed chapter.
The victim list matters too. A university and a regional government body in the same campaign as a water utility is a reminder that education and public-sector networks are on the same target lists as critical infrastructure.
What your institution should do
- Find every on-premises SharePoint server. Include departmental and research farms, not just the central intranet, and check which are reachable from the internet.
- Confirm current patches. Cover both the July 2025 ToolShell fixes and the newer flaws in CISA's July 2026 advisory.
- Rotate ASP.NET machine keys and restart IIS. Do this on any server that was internet-facing and unpatched at any point, even if it is patched now.
- Hunt for web shells. Look for unexpected .aspx files in SharePoint's LAYOUTS directories and unusual processes spawned by the SharePoint worker process.
- Watch for blinding and staging. Alert when security agents stop on many hosts at once, when drivers like K7RKScan load, and when new executables appear in SYSVOL.
- Plan the move off old SharePoint. Servers you cannot keep current should go behind a VPN or be retired.
RSOC is here to help
RSOC can identify internet-facing SharePoint servers, check them against known exploitation indicators, and support incident response if something looks wrong. Contact rsoc@utexas.edu or visit rsoc.utexas.edu.
Sources: Symantec Threat Hunter Team · Security Affairs · The Hacker News · SecurityWeek · DEV Community analysis