đ Contexte
Symantec (Broadcom) publie le 1er octobre 2026 une analyse technique détaillée des activités récentes du groupe Longlegs (alias Storm-2603, anciennement associé aux clusters CL-CRI-1040, CamoFei et ChamelGang), un acteur à nexus chinois responsable du ransomware Warlock, apparu en juin 2025.
đŻ Ciblage
Au cours des deux derniers mois précédant la publication, Longlegs a compromis au moins quatre organisations dans des pays lusophones et hispanophones (Europe, Afrique, Amérique latine) :
- Deux opĂ©rateurs d’infrastructures critiques (une entreprise de distribution d’eau et un opĂ©rateur tĂ©lĂ©com)
- Un gouvernement régional
- Une université
Les victimes prĂ©cĂ©dentes incluaient des organisations aux Ătats-Unis, au BrĂ©sil, en Inde, en Russie, Ă TaĂŻwan et au Japon.
đ Vecteur d’accĂšs initial
Longlegs exploite des vulnĂ©rabilitĂ©s dans Microsoft SharePoint Server on-premises, notamment la chaĂźne d’exploitation ToolShell :
- CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, CVE-2025-53771
- De nouvelles vulnérabilités SharePoint signalées par la CISA en juillet 2026
Le groupe installe un webshell dans le rĂ©pertoire LAYOUTS de SharePoint pour collecter les clĂ©s machine ASP.NET, permettant de forger un payload signĂ© et d’obtenir une exĂ©cution de code arbitraire dans le pool d’application SharePoint.
đ ïž ChaĂźne d’attaque dĂ©taillĂ©e (intrusion juillet 2026)
22 juillet 2026 : Installation d’un webshell sur le serveur SharePoint (Computer 1) via PowerShell encodĂ© en base64.
24 juillet : Reconnaissance (net user /domain, whoami), nettoyage d’artefacts, dĂ©ploiement de paires de DLL sideloading (ssvagent.exe/logger.exe + gsdll64.dll.tmp/doexeloc.dll.tmp ; doexe.exe + doexeloc.dll), Ă©numĂ©ration des trusts AD via nltest.
27 juillet : RequĂȘte vers un sous-domaine oastify.com (Burp Collaborator) pour confirmer l’exĂ©cution de code injectĂ©.
28 juillet : Exploitation complÚte via désérialisation de payload __VIEWSTATE forgé (System.Workflow.ComponentModel), téléchargement de payloads MSI depuis catbox.moe et wasabisys.com via msiexec.
28-29 juillet : Ălargissement au domaine, ajout du compte SPSEPRDSetup au groupe Administrateurs locaux, installation de Visual Studio Code tunnel (code-insiders.exe) pour accĂšs distant furtif, utilisation de NetExec (nxc.exe) pour Ă©numĂ©ration AD et mouvement latĂ©ral.
31 juillet : DĂ©ploiement de l’outil AV/EDR killer (a.exe) exploitant un driver vulnĂ©rable (probablement K7RKScan, CVE-2025-1055) sur au moins 40 hĂŽtes en deux heures, puis dĂ©ploiement du ransomware Warlock (run.exe, rune.exe) via le partage SYSVOL sur au moins 33 hĂŽtes.
đ§° Techniques et outils
- DLL sideloading pour charger du code malveillant en mémoire
- BYOVD (Bring Your Own Vulnerable Driver) avec K7RKScan (CVE-2025-1055)
- Living-off-the-land : net, whoami, nltest, msiexec, cmd
- Visual Studio Code tunnel (code-insiders.exe) pour accĂšs distant furtif
- NetExec (nxc.exe) pour énumération AD et credential spraying
- SYSVOL staging pour déploiement massif du ransomware via réplication DFS
- Téléchargement de payloads depuis des services cloud légitimes (catbox.moe, wasabisys.com)
đ Type d’article
Il s’agit d’une analyse technique approfondie publiĂ©e par l’Ă©quipe Threat Hunter de Symantec/Carbon Black, accompagnĂ©e d’indicateurs de compromission (IOCs) et d’une chronologie dĂ©taillĂ©e d’intrusion, destinĂ©e aux Ă©quipes CTI et SOC.
đ§ TTPs et IOCs dĂ©tectĂ©s
Acteurs de menace
TTP
- T1190 â Exploit Public-Facing Application (Initial Access)
- T1505.003 â Server Software Component: Web Shell (Persistence)
- T1059.001 â Command and Scripting Interpreter: PowerShell (Execution)
- T1574.002 â Hijack Execution Flow: DLL Side-Loading (Defense Evasion)
- T1553.002 â Subvert Trust Controls: Code Signing (Defense Evasion)
- T1562.001 â Impair Defenses: Disable or Modify Tools (Defense Evasion)
- T1068 â Exploitation for Privilege Escalation (Privilege Escalation)
- T1543.003 â Create or Modify System Process: Windows Service (Persistence)
- T1219 â Remote Access Software (Command and Control)
- T1105 â Ingress Tool Transfer (Command and Control)
- T1087.002 â Account Discovery: Domain Account (Discovery)
- T1482 â Domain Trust Discovery (Discovery)
- T1069 â Permission Groups Discovery (Discovery)
- T1078 â Valid Accounts (Defense Evasion)
- T1136 â Create Account (Persistence)
- T1021.002 â Remote Services: SMB/Windows Admin Shares (Lateral Movement)
- T1072 â Software Deployment Tools (Execution)
- T1486 â Data Encrypted for Impact (Impact)
- T1080 â Taint Shared Content (Lateral Movement)
- T1027 â Obfuscated Files or Information (Defense Evasion)
- T1588.002 â Obtain Capabilities: Tool (Resource Development)
- T1036.005 â Masquerading: Match Legitimate Name or Location (Defense Evasion)
IOC
- Domaines :
litter.catbox.moeâ VT · URLhaus · ThreatFox - Domaines :
xn8xyt-drop.s3.wasabisys.comâ VT · URLhaus · ThreatFox - Domaines :
oastify.comâ VT · URLhaus · ThreatFox - URLs :
https://litter.catbox.moe/6f5tdt.msiâ URLhaus - URLs :
https://s3.wasabisys.com/fortifs/vamd64.msiâ URLhaus - URLs :
https://xn8xyt-drop.s3.wasabisys.com/xn8xyt.msiâ URLhaus - SHA256 :
116ca4e88a1bcebb6c0da7fb431c8eca7b8ef3f9767194820c56091972ccac2câ VT · MalwareBazaar - SHA256 :
155fb1cbdaea12c83ba92d18c88cf38bbc42bb684f913ca0bc26fcf115426a55â VT · MalwareBazaar - SHA256 :
1edb2c0b537cd95bbd5fc16321b4c38a6adf325ccc7b588ad6acc980b0463b60â VT · MalwareBazaar - SHA256 :
206f27ae820783b7755bca89f83a0fe096dbb510018dd65b63fc80bd20c03261â VT · MalwareBazaar - SHA256 :
27b7591cf9e1283010ca98fa5dbe970a73fee0d8cde277639924c144718db7c0â VT · MalwareBazaar - SHA256 :
37f94fe1b4a106f02b6f74a69cbc05e69c17406f688beef4c9a045ffcbd2e65eâ VT · MalwareBazaar - SHA256 :
6d07f1232dc59b84038fd0b2e75fdd3d5b825882bb0dba9e6724b7b0823fa3adâ VT · MalwareBazaar - SHA256 :
73c5268256c9da5488cd9e2b79013060ac321c7e54129344dc7b51e268af36eaâ VT · MalwareBazaar - SHA256 :
8b58f7811a2a2f2a5024220490473774f02759dd2dd904b5b9fabfbaae37125fâ VT · MalwareBazaar - SHA256 :
8ce8d8270ee9de02644530b8dd7fa78973b4a3b80f121e2c5f45ae68cce196f9â VT · MalwareBazaar - SHA256 :
9ceb01f8bf7d6dba2ae07f5bd6070de3ec67b5eb01f969b0ba85e74564fb83a7â VT · MalwareBazaar - SHA256 :
aaff04d84ef85353966aa4af186ff1254b72c068f33f802417b29dc23fb9f192â VT · MalwareBazaar - SHA256 :
ae9f7fce57c7b928e659dccf0e00fa79cd9cd61a106f18d4e03f92dc3a03c295â VT · MalwareBazaar - SHA256 :
c46825fcc0d1bf7a8b192facb176d6bf916c9dccfd6fa994be691e3b0e585f4eâ VT · MalwareBazaar - SHA256 :
e14240bac8277b0f6dd4d29ab5da20d246bcccae647e5fe8d19cdae7fe471b20â VT · MalwareBazaar - SHA256 :
e3204b05e2f3a29bb6e6fcc21dda77d7cd31dfa755c21da0aa8661b5619ee0a1â VT · MalwareBazaar - SHA256 :
eea631b5f7125239db0811e4682c2316ead69f9822e02d94fb5d8bf0d2faebedâ VT · MalwareBazaar - SHA256 :
f7269f80f81e99d06a590d7ab374e12fdf7e5f55a02c2a46c342d670f8519fdfâ VT · MalwareBazaar - SHA256 :
fb3846c9ac53d1b841ada3a6b1091153fea41a169cb44fe0084097d1f4d45984â VT · MalwareBazaar - CVEs :
CVE-2025-49704â NVD · CIRCL - CVEs :
CVE-2025-49706â NVD · CIRCL - CVEs :
CVE-2025-53770â NVD · CIRCL - CVEs :
CVE-2025-53771â NVD · CIRCL - CVEs :
CVE-2025-1055â NVD · CIRCL - Fichiers :
layout2sp.aspx - Fichiers :
doexeloc.dll - Fichiers :
ssvagent.exe - Fichiers :
logger.exe - Fichiers :
gsdll64.dll.tmp - Fichiers :
doexeloc.dll.tmp - Fichiers :
doexe.exe - Fichiers :
code-insiders.exe - Fichiers :
nxc.exe - Fichiers :
a.exe - Fichiers :
run.exe - Fichiers :
rune.exe - Fichiers :
how to restore your files.txt - Chemins :
CSIDL_PROGRAM_FILES_COMMON\microsoft shared\web server extensions\14\template\layouts\layout2sp.aspx - Chemins :
CSIDL_SYSTEM\0409\ssvagent.exe - Chemins :
CSIDL_SYSTEM\0409\logger.exe - Chemins :
CSIDL_WINDOWS\debug\code-insiders.exe - Chemins :
C:\users\public\a.exe - Chemins :
C:\users\public\run.exe - Chemins :
C:\users\public\rune.exe - Chemins :
CSIDL_WINDOWS\SYSVOL\domain\scripts\run\run.exe - Chemins :
CSIDL_WINDOWS\SYSVOL\domain\scripts\run\rune.exe
â ïž Ă propos de ces IOC â ils sont extraits automatiquement de l’article original le 5 octobre 2026 et n’ont pas fait l’objet d’une vĂ©rification externe. Un indicateur peut avoir Ă©tĂ© rĂ©attribuĂ© depuis : une IP de C2 peut redevenir un service lĂ©gitime, un domaine sinkholĂ© peut changer de propriĂ©taire. Aucune garantie d’exactitude ni d’actualitĂ© â contrĂŽlez leur validitĂ© avant tout usage opĂ©rationnel, en particulier avant de les injecter dans une blocklist ou un SIEM.
Malware / Outils
- Warlock (ransomware)
- K7RKScan (tool)
- NetExec (framework)
- Visual Studio Code tunnel (tool)
- doexe.exe (loader)
- ssvagent.exe (loader)
- a.exe (tool)
đą Indice de vĂ©rification factuelle : 80/100 (haute)
- ⏠security.com â source non rĂ©fĂ©rencĂ©e (0pts)
- â 16890 chars â texte complet (fulltext extrait) (15pts)
- â 52 IOCs dont des hashes (15pts)
- â 3/9 IOCs confirmĂ©s (MalwareBazaar, ThreatFox, URLhaus, VirusTotal) (15pts)
- â 22 TTPs MITRE identifiĂ©es (15pts)
- â date extraite du HTML source (10pts)
- â acteur(s) identifiĂ©(s) : Longlegs, Storm-2603 (5pts)
- â 5/5 CVE(s) confirmĂ©e(s) (CIRCL) (5pts)
IOCs confirmés externellement :
litter.catbox.moe(domain) â VT (5/91 dĂ©tections)xn8xyt-drop.s3.wasabisys.com(domain) â VT (4/91 dĂ©tections)oastify.com(domain) â VT (6/91 dĂ©tections)
đ Source originale : https://www.security.com/threat-intelligence/warlock-ransomware-critical-infrastructure