Warlock’s nine-day SharePoint intrusion, and the dark-web trail behind it

A host-by-host reconstruction of Warlock’s July 2026 attack on a critical-infrastructure operator, set against 78 leak-site listings, underground forum chatter and the group’s actor profile — with an ATT&CK mapping, hunting queries and indicators to download.

Key judgments

  • High confidenceWarlock sells first and leaks second. Twenty-seven of the 78 leak-site listings in our collection say the data went to “other buyers (not victims)”; the operators publish only when no one pays and no one buys.
  • High confidenceThe leak site has stopped tracking Warlock’s tempo. Its most recent listing is dated 26 January 2026, yet the group breached SmarterTools three days later and a critical-infrastructure operator in July.
  • High confidenceDefenders had days, not minutes. In the July intrusion at least four distinct, detectable steps came before protection was switched off on 31 July — after which the estate fell in about two hours.
  • Moderate confidenceInitial access follows exposure more than sector. SharePoint and SmarterMail were both reached through unpatched internet-facing servers, and the leak site lists victims in at least ten countries. Symantec’s 2026 cluster of Portuguese- and Spanish-speaking victims could still reflect deliberate tasking.
  • No assessmentWe have no independent basis to go beyond Microsoft’s moderate-confidence view that Storm-2603 is China-based, and we make no judgment on state direction.
from the first web shell to ransomware
9 days
hosts with protection disabled in about two hours
≥ 40
leak-site listings in our collection, 27 marked as sold
78
new listings since 26 January 2026, while the intrusions continued
0

On 1 October 2026, Symantec and Carbon Black published the most detailed account yet of a Warlock intrusion: a critical-infrastructure operator whose SharePoint servers were compromised on 22 July and whose estate was running ransomware nine days later. BleepingComputer carried the story the next day. This analysis adds what those reports do not have — the group’s own leak-site record, the underground forums that track it, and FireIntel’s actor profile — and turns the July chronology into an ATT&CK mapping, hunting queries and machine-readable indicators.

Evidence assessment
StatusFindingSource
ObservedA web shell on 22 July; an AV/EDR killer on at least 40 hosts and Warlock on at least 33 by 31 July.Symantec / Carbon Black telemetry, one intrusion
Observed78 leak-site listings dated by the site between 28 July 2025 and 26 January 2026; 27 marked as sold.FireIntel DDW Advance collection
ObservedA SmarterMail authentication bypass used to stage Velociraptor ahead of Warlock, intercepted before encryption.ReliaQuest, February 2026
AssessedSharePoint exploitation was the July entry route; Longlegs is the actor Microsoft tracks as Storm-2603.Symantec; Microsoft
UnknownThe exact 2026 entry CVE, the July case’s driver, the victims’ identities, service impact and any ransom outcome.Not established in the primary report

Nine days, host by host

The first recorded malicious act came on 22 July 2026, when PowerShell wrote a web shell named layout2sp.aspx into the SharePoint LAYOUTS directory. The group writes its shell into the folders of several SharePoint versions at once, so it runs whichever version is installed; its job is to harvest the farm’s ASP.NET machine keys, which let the attackers forge a validly signed payload and run code inside the SharePoint application pool.

Incident chronology · analyst reconstruction
  • Intrusion activity
  • Protection disabled, ransomware deployed
Host-by-host chronology of the July 2026 Warlock intrusionTwelve numbered events from 22 to 31 July 2026 across two SharePoint servers, three further hosts and the wider estate. Activity starts with a web shell on 22 July, pauses on 25 and 26 July, builds through 28 and 29 July, and ends on 31 July with security tools disabled on at least 40 hosts and Warlock deployed on at least 33.July 202622232425262728293031SharePoint server 1first footholdSharePoint server 2staging and toolingHosts 3–5expansionEstateprotection disabledEstateransomwareno activityrecorded123456789101112Nine days from the first web shell to ransomware on the estate
  1. 22 Jul · SharePoint server 1

    PowerShell writes the layout2sp.aspx web shell into the SharePoint LAYOUTS directory.

  2. 24 Jul · SharePoint server 2

    Domain reconnaissance (net user /domain, whoami); staging files deleted; ssvagent.exe and logger.exe staged for DLL side-loading.

  3. 24 Jul · SharePoint server 1

    The SharePoint worker drops a doexe.exe / doexeloc.dll side-loading pair and runs nltest /domain_trusts. The pair is still running on 30–31 July.

  4. 27 Jul · SharePoint server 2

    Out-of-band canary: a request to an oastify.com subdomain that embeds the victim’s own domain name.

  5. 28 Jul, morning · SharePoint server 2

    The attackers return to re-test the web shell.

  6. 28 Jul, afternoon · SharePoint servers 1 and 2

    System.Workflow.ComponentModel is loaded repeatedly — the deserialization gadget that turns a forged, machine-key-signed __VIEWSTATE into code execution.

  7. 28 Jul · SharePoint server 2

    Three MSI packages pulled from catbox.moe and Wasabi storage within about 90 minutes.

  8. 28–29 Jul · Hosts 3, 4 and 5

    Domain account SPSEPRDSetup — named to look like a SharePoint setup account — repeatedly added to local Administrators.

  9. 29 Jul, evening · Host 4

    VS Code Insiders installed as a tunnel service from C:\Windows\debug — remote access relayed through Microsoft infrastructure.

  10. 29 Jul, evening · SharePoint server 2

    NetExec runs Active Directory enumeration, password spraying and remote command execution.

  11. 31 Jul, early hours · ≥ 40 hosts

    a.exe, an AV/EDR killer copied from an internal share, runs across the estate in about two hours.

  12. 31 Jul · ≥ 33 hosts

    run.exe and rune.exe launch from the SYSVOL scripts folder with the note “how to restore your files.txt”; three hosts show DFS Replication as the delivering parent.

Reconstructed from the Symantec and Carbon Black telemetry for one intrusion. Positions within a day are approximate; these are the recorded milestones, not a complete record of attacker activity.

The pace is patient, then sudden. Reconnaissance and DLL side-loading on 24 July were followed by two silent days. On 27 July an out-of-band request to oastify.com — Burp Collaborator, with the victim’s own domain baked into the subdomain — confirmed that injected code had run. On 28 July a deserialization gadget turned a forged __VIEWSTATE into code execution, and three MSI packages arrived from public file hosts within ninety minutes. Over the next day a look-alike account, SPSEPRDSetup, joined local Administrators on three more hosts; VS Code Insiders was installed as a tunnel service; and NetExec mapped Active Directory and sprayed passwords.

Then, in the early hours of 31 July, an AV/EDR killer copied from an internal share ran on at least 40 hosts in about two hours, and Warlock — run.exe, rune.exe and a note called “how to restore your files.txt” — appeared on at least 33. The payload had been staged in SYSVOL, which replicates to every domain controller: on three hosts the DFS Replication service itself was recorded delivering it.

What the dark web shows

We queried FireIntel’s DDW Advance collection for Warlock across ransomware leak sites and underground forums on 3 October 2026. The leak-site search returns 78 listings. Each record carries the leak site’s own date for the listing separately from the date it was collected, and we checked both: the listings are dated 28 July 2025 to 26 January 2026, while collection ran well into 2026. In every capture below, victim names are covered with fixed-width bars so that not even their length gives anything away; a domain suffix such as .ru or .local is left visible where it carries analytic value, and onion addresses are withheld.

Source: FireIntel DDW Advance · captured 3 Oct 2026Open full image
DDW Advance search for warlock with the source type set to ransomware, returning 78 leak-site entries whose victim names are covered by solid bars
DDW Advance, ransomware sources, query “warlock”: 78 results. The first five listings are shown; victim names are covered and only their domain suffixes are left visible.

Read the listings rather than counting them and the operators’ business model surfaces. Each carries a short status line written by the operators themselves, and four kinds recur:

  • “The data has been bought by other buyers (not victims)” — 25 listings, plus two worded “purchased by other buyers”: 27 sales in all, every one dated July or August 2025.
  • “The customer has not paid, and there are no other buyers within the validity period” — the data is then published for anyone to take. Two listings.
  • Partial leaks offered as samples, with the full set “to be purchased separately” — one of them advertised as an auction of a million documents.
  • The rest give only a data volume or “all data”, with no status at all.
Source: FireIntel DDW Advance · selected listingsOpen full image
Five Warlock leak-site entries with victim names covered, showing status lines for data sold to other buyers, data published after non-payment, and partial leaks sold separately or by auction
Five selected listings and their status lines: sold to other buyers, published once the payment window lapsed, and partial leaks sold as samples or by auction.

Sophos counted the same number of sales, 27, by mid-September 2025. Neither collection names the buyers, so we cannot confirm the two counts cover identical listings, but the agreement is strong. The more telling signal is that the sales stop after August: either buyers dried up or the operators stopped advertising sales in public. What the status lines do show is the leverage. A victim who refuses to pay does not get its data back unpublished — it goes to the highest bidder or, failing one, to everyone.

Two smaller details deserve attention. Six listings are named after internal Active Directory domains ending in .local or .home rather than public websites — a sign the operators named those victims from inside the network, most likely from a domain controller. And the public domains span at least ten country codes: Australia, Bolivia, Canada, Czechia, Japan, Russia, Taiwan, the UAE, the United Kingdom and the United States. That breadth matches the geography researchers reported in 2025; the 2026 cluster of Portuguese- and Spanish-speaking victims that Symantec describes is not visible on a leak site that has been silent since January.

What the forums say

Underground forums keep their own score. On 31 January 2026, a user on a forum presenting itself as a relaunch of XSS answered a question about which ransomware groups were still active with a tracker table pasted as plain text: each group’s first and last victim, its victim counts over 7, 30 and 90 days, and whether its site was up. We have set the relevant rows out below.

Selected rows from the 31 January 2026 forum tracker
GroupFirst victimLast victim7 days30 days90 daysSite
clop2020-03-132026-01-254346145Online
safepay2023-11-102026-01-2671193Online
lockbit52024-08-172026-01-210779Online
dragonforce2022-10-202026-01-240867Online
play2022-11-262026-01-2671964Online
everest2021-09-092026-01-2102147Online
medusa2023-01-112026-01-040117Online
warlock2025-04-022025-11-06008Online
lockbit32021-12-262025-12-05001Online

Group names and figures are the tracker’s own, transcribed from the post; it does not say how it counts victims. Rows are selected for comparison from a list of dozens of groups.

Source: FireIntel DDW Advance · forum excerptOpen full image
Excerpt of the forum tracker post as captured, with the Warlock row highlighted: first victim 2 April 2025, last victim 6 November 2025, 0, 0 and 8 victims, online
The source line as captured, with Warlock’s row highlighted. The post pastes the whole table as running text, which is why we set it out above.

By the tracker’s numbers, Warlock was a small operator at the end of January: eight victims in 90 days and none in the last 30, against 145 for Clop and 79 for LockBit 5. But the tracker had missed something. It puts Warlock’s last victim at 6 November 2025, while the leak site itself dated 17 listings in January 2026, the latest on 26 January — five days before the post. Secondary trackers lag the sites they count. Its first-victim date, 2 April 2025, two months before Warlock’s public debut, is a second reason to treat it as a lead rather than a record.

Eighteen months of Warlock activity

Campaign timeline · public reporting and FireIntel collection
  • Leak-site entries in FireIntel’s collection
  • Public reporting
  • Documented intrusion
Warlock activity from April 2025 to October 2026Monthly Warlock leak-site entries in FireIntel’s collection: 27 in July 2025, 23 in August, 11 in September, none from October to December, 17 in January 2026 and none after that. Ten numbered events from public reporting — four of them intrusions — are marked above the columns, from the LockBit affiliate account in April 2025 to Symantec’s report on 1 October 2026.0102030Leak-site entries per monthReportsAttacksnone indexedno new entries indexedJul 2025: 27 leak-site entries27Aug 2025: 23 leak-site entries23Sep 2025: 11 leak-site entries11Jan 2026: 17 leak-site entries17Apr2025MayJunJulAugSepOctNovDecJan2026FebMarAprMayJunJulAugSepOct12345678910
  1. 22 Apr 2025 · Unit 42

    An account named “wlteaml” is registered on LockBit 3.0’s affiliate panel; it shares the Tox ID later embedded in AK47 ransom notes.

  2. 10 Jun 2025 · Sophos

    Warlock appears on the RAMP forum seeking exploits and EDR killers; its first leak site goes online and drops offline a day later.

  3. 18 Jul 2025 · Microsoft

    Storm-2603 begins deploying ransomware through the ToolShell SharePoint zero-days. Our first leak-site entry follows ten days later.

  4. 16 Sep 2025 · Sophos

    60 victims listed; 27 marked as sold to private buyers rather than published.

  5. Jan 2026 · Trend Micro

    A SharePoint intrusion leads to Cobalt Strike, Velociraptor, a Cloudflare tunnel and a new BYOVD driver before Warlock is pushed by Group Policy.

  6. 29 Jan 2026 · SmarterTools

    Warlock breaches the mail-software vendor SmarterTools itself, through a forgotten, unpatched SmarterMail virtual machine.

  7. Feb 2026 · ReliaQuest

    Storm-2603 chains a SmarterMail authentication bypass (CVE-2026-23760) with the Volume Mount feature to install Velociraptor — Warlock staging, caught before encryption.

  8. 14 Jul 2026 · CISA

    CISA urges SharePoint hardening after three newly exploited vulnerabilities.

  9. 22–31 Jul 2026 · Symantec

    The critical-infrastructure intrusion charted above: web shell to Warlock in nine days.

  10. 1 Oct 2026 · Symantec

    Four recent victims disclosed: a water utility, a telecom operator, a regional government body and a university.

Columns count Warlock leak-site listings in FireIntel’s collection by the date the site gave each listing — criminal claims, not confirmed victims. Numbered markers are dated events from the public reports listed under Sources.

Laid end to end, the record shows an operation that went public fast. Warlock announced itself in June 2025, was exploiting the ToolShell zero-days within six weeks, and had a working leak site by late July. Our first listing is dated 28 July 2025; by the end of September there were 61, against the 60 that Sophos counted by mid-September.

Then the record thins. Our collection holds no listings dated October to December 2025, although the forum tracker recorded a Warlock victim on 6 November — so this is leak-site downtime or a gap in collection, not a proven pause. Seventeen listings are dated January 2026, and none since. The intrusions did not stop: Trend Micro documented one in January 2026, ReliaQuest another in February, Symantec the July case. Whatever the reason — new infrastructure, more private sales, or victims settling quietly — the leak site is no longer a reliable gauge of Warlock’s tempo.

Not only SharePoint

The front door is whichever internet-facing Windows application is behind on patches. On 29 January 2026, Warlock breached SmarterTools, the company that makes the SmarterMail mail server, through a SmarterMail virtual machine an employee had set up and nobody was updating. On 9 February, ReliaQuest attributed SmarterMail exploitation it had observed to Storm-2603 with moderate-to-high confidence: an authentication bypass, CVE-2026-23760, chained with the product’s own Volume Mount feature to run commands as the mail service, pull an MSI from Supabase and install Velociraptor as a backdoor. No ransomware was deployed in the case it describes; the staging matched earlier Warlock intrusions step for step.

The research travelled. Within weeks it was being retold, in Russian, on underground forums we collect from. Forum audiences read vendor research closely: the write-up that helps defenders patch also tells other crews which servers are worth scanning for.

Source: FireIntel DDW Advance · captured 3 Oct 2026Open full image
Russian-language forum thread from 25 February 2026 summarising Storm-2603’s exploitation of a SmarterMail authentication bypass ahead of Warlock ransomware
A 25 February 2026 forum thread retelling the SmarterMail research in Russian: Storm-2603, CVE-2026-23760, and the vulnerable builds before 9511.

Who is behind Warlock

Actor naming · source-backed assessment
How research teams name the actor behind WarlockFour research names for the same actor — Longlegs (Symantec), Storm-2603 (Microsoft, China-based with moderate confidence), GOLD SALEM (Sophos) and CL-CRI-1040 (Unit 42) — point to the Warlock operation. On the other side are its links: earlier CamoFei and ChamelGang clusters, a LockBit 3.0 affiliate account and LockBit Black payloads, and the Project AK47 toolset. The older Warlock Dark Army ransomware is unrelated.Names for the same actorLineage and toolingLonglegsSymantec and Carbon BlackOctober 2026 reportStorm-2603Microsoft: China-based,moderate confidenceGOLD SALEMSophos Counter Threat Unittracks the leak-site operationCL-CRI-1040Unit 42: same actor asStorm-2603, high confidenceCamoFei / ChamelGangearlier clusters, linked by ashared code-signing certificateLockBit 3.0affiliate account “wlteaml”;LockBit Black payloadsProject AK47AK47C2 backdoor,X2ANYLOCK ransomwareWarlock Dark Armyolder ransomware namenot relatedWarlockransomware operationfirst seen June 2025Names are research labels for overlapping activity; none of them is, by itself, evidence of state direction.
Analyst map of public research. Connectors show the relationship each team reports; they are not a measure of certainty, which the text gives source by source.

Symantec calls the actor Longlegs and treats it as the group Microsoft tracks as Storm-2603. Microsoft assesses Storm-2603 as China-based with moderate confidence and has found no link to the separately tracked Linen Typhoon or Violet Typhoon. Unit 42 assesses with high confidence that its CL-CRI-1040 cluster is the same actor, while stating it cannot attribute the cluster to any nation-state. Sophos tracks the operator as GOLD SALEM and dates Warlock’s public debut to 10 June 2025, on the RAMP forum.

The lineage is older than the brand. Symantec has traced a stolen code-signing certificate used by Warlock operators back to the CamoFei and ChamelGang clusters, active since at least 2019. Unit 42 found an affiliate account called “wlteaml” in leaked LockBit 3.0 panel data, registered in April 2025 and sharing a Tox ID with AK47 ransom notes, and Check Point documented the group running LockBit Black alongside Warlock. The older “Warlock Dark Army” ransomware is unrelated.

The actor profile in our collection

FireIntel’s profile of the group records Warlock from 10 June 2025 — the day Sophos dates its RAMP debut and first leak site — and summarises the attribution picture: Storm-2603, a history with LockBit, and an overlap in victims with Black Basta, read as an “old affiliate” that went on to build its own encryptor. All four known sites, three leak-site addresses under the “Client Data Leak Show” name and a file portal, are reported offline.

Source: FireIntel Threat actors · captured 3 Oct 2026Open full image
FireIntel threat-actor profile for Warlock showing the date it was added, the attribution overview and four known sites, all reported offline, with onion addresses covered
The Warlock profile in the Threat actors view. Onion addresses are covered; the offline status of all four known sites is left visible.

A profile summary is an analysis, and we weigh it like any other source. Its Storm-2603 and LockBit links match Microsoft’s and Unit 42’s reporting; the Black Basta victim overlap is not established by the research cited here, so we carry it as a lead. The same discipline applies to the tooling the profile data associates with the group. The table separates what independent reporting corroborates from what it does not.

Tooling in the profile data, against independent reporting
CategoryTools in the profileAlso reported by
Credential theftMimikatz; Veeam-Get-CredsMimikatz: Microsoft, Sophos, Trend Micro
Defense evasionAntiy, NSec and Rising drivers (BYOVD); a VMTools-based AV killerAntiy driver: Check Point · NSec driver: Trend Micro
DiscoveryEverything.exe; SecurityCheck—
ExfiltrationRcloneTrend Micro
Built-in toolsMinidump, msiexec, PowerShell Remoting, PsExec, RDP Patchermsiexec: Symantec, ReliaQuest · PsExec: Microsoft, Trend Micro · Remoting, RDP Patcher: Trend Micro
Tunnels and storageAzure Blob Storage, Catbox, Cloudflared, MinIO, OpenSSH, Supabase, VS Code tunnel, YuzeVS Code tunnel: Symantec, Sophos, Trend Micro · Catbox: Symantec · Supabase: ReliaQuest · Cloudflared, Yuze: Trend Micro
FrameworksCobalt Strike, VelociraptorVelociraptor: Sophos, Trend Micro, ReliaQuest · Cobalt Strike: Trend Micro
Remote managementRadmin, TightVNCTightVNC: Trend Micro

Uncorroborated entries — Veeam-Get-Creds, the Rising driver, the VMTools-based AV killer, Everything.exe, SecurityCheck, Azure Blob Storage, MinIO, OpenSSH and Radmin — are hunting leads, not evidence of use.

Four vulnerable drivers in fifteen months

2025 · Check Point
A signed Antiy Labs driver behind the “Antivirus Terminator” tool
2025 · Sophos, Symantec
A 2016 Baidu antivirus driver renamed googleApiUtil64.sys (CVE-2024-51324)
Jan 2026 · Trend Micro
NSecKrnl.sys, loaded by a fake TrendSecurity.exe to kill more than 30 security processes
2026 · Symantec
K7RKScan (CVE-2025-1055); the driver used in the July case is unidentified

The rotation matters more than any single name on that list. Blocking one driver buys little; enforcing Microsoft’s vulnerable driver blocklist with memory integrity (HVCI) turned on, and alerting on any new kernel driver load on servers, closes the class.

Detection and response

Each technique below is tied to an artefact in the published telemetry for the July intrusion, not inferred from the group’s wider reputation. Where the report stops short — the exact CVE, the driver behind the AV/EDR killer — the mapping stops short too.

Techniques observed in the 22–31 July intrusion
TacticTechniqueEvidence in this case
Initial accessT1190Exploit Public-Facing ApplicationOn-premises SharePoint exploitation, assessed as the likely route; the exact 2026 CVE is not identified.
PersistenceT1505.003Web Shelllayout2sp.aspx written into the SharePoint LAYOUTS directory on 22 July.
ExecutionT1059.001PowerShellEncoded PowerShell writes the web shell and loads the ViewState deserialization gadget.
DiscoveryT1087.002Domain Accountnet user /domain and whoami on the second SharePoint server.
DiscoveryT1482Domain Trust Discoverynltest /domain_trusts alongside the first side-loading pair.
Defense evasionT1574Hijack Execution Flow (DLL side-loading)doexe.exe with doexeloc.dll; ssvagent.exe and logger.exe with their DLLs.
Defense evasionT1070.004File DeletionNumerically named staging files and doexeloc.dll removed on 24 July.
Command and controlT1105Ingress Tool Transfermsiexec pulls three MSI packages from catbox.moe and Wasabi storage.
PersistenceT1098Account ManipulationSPSEPRDSetup repeatedly added to local Administrators on three hosts.
Defense evasionT1036MasqueradingThe account name imitates SharePoint’s SPS-prefixed service accounts.
Command and controlT1572Protocol Tunnelingcode-insiders.exe tunnel service install, from C:\Windows\debug.
Credential accessT1110.003Password SprayingNetExec credential spraying against Active Directory.
Lateral movementT1021.002SMB / Windows Admin Sharesnet use to an internal IP, then copy of the \av tool set to each host.
Defense evasionT1562.001Disable or Modify Toolsa.exe AV/EDR killer on at least 40 hosts, likely through a vulnerable driver.
Lateral movementT1570Lateral Tool TransferPayload staged in SYSVOL\scripts\run and delivered by DFS Replication.
ImpactT1486Data Encrypted for Impactrun.exe and rune.exe on at least 33 hosts, with the ransom note.

For on-premises SharePoint, Microsoft’s guidance is current patches, AMSI integration in Full Mode, Defender or an equivalent on every SharePoint server, then a machine-key rotation and an IIS restart. CISA’s July 2026 alert adds the order that matters: if compromise is suspected, find and remove web shells and machine-key harvesters before rotating keys, or the attacker simply reads the new ones. For SmarterMail, ReliaQuest’s advice is build 9511 or later and strict isolation of mail servers. Patching closes the door; it does not evict anyone already inside.

Windows telemetry worth alerting on

New .aspx in LAYOUTS
File creation under …\web server extensions\…\TEMPLATE\LAYOUTS (Sysmon 11 or EDR file events)
IIS spawning tools
w3wp.exe starting cmd.exe, powershell.exe, msiexec.exe or nltest.exe
Mail service spawning a shell
MailService.exe starting cmd.exe or msiexec.exe on a SmarterMail server
Local admin changes
Security event 4732 on servers, especially SP-prefixed accounts outside change windows
New services
System event 7045 — a code or code-insiders tunnel service is never routine on a server
Kernel drivers
Sysmon 6 or EDR driver loads on servers; any new driver deserves a look
SYSVOL
New executables under SYSVOL\…\scripts, and processes whose parent is dfsrs.exe

For Microsoft Defender XDR, the advanced-hunting queries below turn those signals into searches. Each was checked with Microsoft’s Kusto language parser against the Defender table schema; none has been run against live telemetry for this post, so they are deliberately broad — expect to tune out your own administration tooling before alerting on them.

Web shells written into SharePoint LAYOUTSKQL
DeviceFileEvents
| where Timestamp > ago(30d)
| where FolderPath has @"\web server extensions\" and FolderPath has @"\template\layouts\"
| where FileName endswith ".aspx"
| project Timestamp, DeviceName, FolderPath, FileName,
          InitiatingProcessFileName, InitiatingProcessCommandLine
IIS or SmarterMail launching shells, installers or domain toolsKQL
DeviceProcessEvents
| where Timestamp > ago(30d)
| where InitiatingProcessFileName in~ ("w3wp.exe", "MailService.exe")
| where FileName in~ ("cmd.exe", "powershell.exe", "pwsh.exe", "msiexec.exe", "nltest.exe")
| project Timestamp, DeviceName, InitiatingProcessFileName, FileName,
          ProcessCommandLine, InitiatingProcessCommandLine
VS Code tunnels, file-host installers and SYSVOL-delivered payloadsKQL
DeviceProcessEvents
| where Timestamp > ago(30d)
| where (FileName in~ ("code.exe", "code-insiders.exe")
         and ProcessCommandLine has_all ("tunnel", "service", "install"))
    or (FileName =~ "msiexec.exe"
         and ProcessCommandLine has_any ("catbox.moe", "wasabisys.com", "supabase.co"))
    or (InitiatingProcessFileName =~ "dfsrs.exe" and FileName endswith ".exe")
| project Timestamp, DeviceName, AccountName, FileName, ProcessCommandLine,
          InitiatingProcessFileName
  • Take SharePoint and mail servers off the open internet where you can. If they must stay reachable, put them behind an authenticated layer-7 proxy and block external access to SharePoint Central Administration.
  • Hunt before you rotate: web shells, machine-key harvesters and unexpected ASPX files first, then new machine keys and an IIS restart on every server in the farm.
  • Review local Administrators membership on SharePoint and adjacent servers against a known-good baseline, and alert on changes.
  • Treat the 31 July pattern — one share copied to dozens of hosts in minutes — as a tripwire. Mass execution of the same binary from C:\Users\Public is rarely legitimate.

Indicators

Machine-readable indicators

  • CSV 32 indicators with type, classification, context and source
  • STIX 2.1 bundle Indicators, the Warlock malware family and the Storm-2603 intrusion set, with relationships; TLP:CLEAR

The primary report’s IOC appendix lists 19 SHA-256 hashes: five Warlock payloads, six malicious DLLs, six suspicious files, one AV/EDR killer and one vulnerable driver. They are reproduced below under the source’s own classifications. This is a report-wide set rather than a list of files from the 22–31 July case, and the report does not map every hash to a filename. A match warrants investigation; a non-match clears nothing, because this group changes tooling.

File indicators19 SHA-256 hashes

Warlock payload

5 hashes
  • 116ca4e88a1bcebb6c0da7fb431c8eca7b8ef3f9767194820c56091972ccac2c
  • 155fb1cbdaea12c83ba92d18c88cf38bbc42bb684f913ca0bc26fcf115426a55
  • 6d07f1232dc59b84038fd0b2e75fdd3d5b825882bb0dba9e6724b7b0823fa3ad
  • 8b58f7811a2a2f2a5024220490473774f02759dd2dd904b5b9fabfbaae37125f
  • 8ce8d8270ee9de02644530b8dd7fa78973b4a3b80f121e2c5f45ae68cce196f9

Malicious DLL

6 hashes
  • 1edb2c0b537cd95bbd5fc16321b4c38a6adf325ccc7b588ad6acc980b0463b60
  • 206f27ae820783b7755bca89f83a0fe096dbb510018dd65b63fc80bd20c03261
  • 27b7591cf9e1283010ca98fa5dbe970a73fee0d8cde277639924c144718db7c0
  • c46825fcc0d1bf7a8b192facb176d6bf916c9dccfd6fa994be691e3b0e585f4e
  • e14240bac8277b0f6dd4d29ab5da20d246bcccae647e5fe8d19cdae7fe471b20
  • fb3846c9ac53d1b841ada3a6b1091153fea41a169cb44fe0084097d1f4d45984

Suspicious file

6 hashes
  • 37f94fe1b4a106f02b6f74a69cbc05e69c17406f688beef4c9a045ffcbd2e65e
  • 9ceb01f8bf7d6dba2ae07f5bd6070de3ec67b5eb01f969b0ba85e74564fb83a7
  • aaff04d84ef85353966aa4af186ff1254b72c068f33f802417b29dc23fb9f192
  • e3204b05e2f3a29bb6e6fcc21dda77d7cd31dfa755c21da0aa8661b5619ee0a1
  • eea631b5f7125239db0811e4682c2316ead69f9822e02d94fb5d8bf0d2faebed
  • f7269f80f81e99d06a590d7ab374e12fdf7e5f55a02c2a46c342d670f8519fdf

AV/EDR killer

1 hash
  • 73c5268256c9da5488cd9e2b79013060ac321c7e54129344dc7b51e268af36ea

Vulnerable driver

1 hash
  • ae9f7fce57c7b928e659dccf0e00fa79cd9cd61a106f18d4e03f92dc3a03c295

SharePoint intrusion: network indicators and delivery paths (Symantec)

Appendix host
litter[.]catbox[.]moe
Appendix host
xn8xyt-drop[.]s3[.]wasabisys[.]com
MSI 1, 28 Jul
hxxps://litter[.]catbox[.]moe/6f5tdt.msi
MSI 2, 28 Jul
hxxps://s3[.]wasabisys[.]com/fortifs/vamd64.msi
MSI 3, 28 Jul
hxxps://xn8xyt-drop[.]s3[.]wasabisys[.]com/xn8xyt.msi

SmarterMail activity: infrastructure (ReliaQuest, February 2026)

Domain
auth[.]qgtxtebl[.]workers[.]dev
Domain
vdfccjpnedujhrzscjtq[.]supabase[.]co
Domain
2-api[.]mooo[.]com
IP addresses
162.252.198[.]197 · 199.217.99[.]93 · 157.245.156[.]118 · 45.127.35[.]186 · 178.128.103[.]218

Method, confidence and limits

The July chronology, host counts and IOC appendix come from Symantec and Carbon Black; the SmarterMail activity and its indicators from ReliaQuest; actor naming and history from Microsoft, Unit 42, Sophos, Check Point, Trend Micro and Symantec’s earlier research. Each is cited where it is used, and every indicator was checked against its source. Leak-site and forum figures come from FireIntel’s DDW Advance collection as queried on 3 October 2026; listings are dated by the leak site, counted as claims rather than confirmed victims, and the collection can have gaps.

Confidence follows common intelligence practice. High confidence means the judgment rests on direct observation in our collection or on several independent sources that agree. Moderate means the evidence is credible but incomplete, or comes from a single source. Low means the judgment is plausible but thinly supported. “No assessment” means we lack an independent basis to judge.

The diagrams are analyst reconstructions. Screenshots were captured from the FireIntel console on 3 October 2026 and redacted before publication: victim names are covered with fixed-width bars and onion addresses are withheld. Beyond choosing which listings to show and highlighting the Warlock row of the forum tracker, nothing in them was altered. No unnamed victim in the Symantec report is identified here.

Sources