INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
China-linked ransomware attacks breach Secure Point in Seoul infrastructure
| 2026-10-04 11:53 CRITICAL HIGH RANSOMWARE & EXTORTION STATE-SPONSORED & ESPIONAGE
Executive Summary
AI-generated
A Chinese-linked attack group, identified as 'Longlegs' or 'Storm-2603', has been targeting at least four institutions in countries that use Portuguese and Spanish languages, primarily in Europe and Africa, and South America over the past two months. The attackers exploited a vulnerability in Microsoft SharePoint servers to breach critical infrastructure, including water and telecommunications companies, local government agencies, and universities. They used the tunneling feature of Visual Studio Code development tool to create a hidden backdoor that allowed them to access internal systems from outside, and installed ransomware on at least 33 systems, specifically targeting system volume (SYSVOL) in Windows domain environments. The attackers deployed 'Warlock' ransomware on a large scale after disabling security products, including antivirus, endpoint detection and response systems, and executing a disable tool on at least 40 systems for 2 hours.
Technical Mitigations AI-generated
• Apply the vendor fix for CVE-2025-3248 and treat internet-facing systems that were not patched in time as potentially compromised until verified.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2025-3248CVE-2025-3248
Target & Sectors
LATAM
LATAM
EUROPE
EUROPE
AFRICA
AFRICA
educationeducation
governmentgovernment
telecommunicationstelecommunications
Incident Timeline
early June 2026
Threat actors used an unspecified ransomware strain to breach Secure Point's systems in early June 2026, targeting key infrastructure and telecommunications in Seoul.
Click on any entity below to view its context and source!
general_metric
18 hours
The attack took place in early June 2026 over a period of about 18 hours.
2026/10/04
China-linked ransomware attacks breached Secure Point, targeting key infrastructure in Seoul and telecommunications.
Click on any entity below to view its context and source!
organisation
Secure Point
China-linked ransomware attacks breached Secure Point, targeting key infrastructure in Seoul and telecommunications..
organisation
Microsoft SharePoint
A Chinese-linked attack group has exploited a vulnerability in Microsoft SharePoint servers to breach critical infrastructure, including water and telecommunications companies, and deployed the 'Warlock' ransomware on a large scale, according to a confirmed incident.
organisation
Storm-2603
According to the Samtanek threat hunting team, the attackers, identified as 'Longlegs' or 'Storm-2603', have been targeting at least four institutions, including water and telecommunications companies, local government agencies, and universities, over the past two months.
infrastructure
Windows
The attackers specifically installed ransomware on the system volume (SYSVOL) in the Windows domain environment, where policies and files are shared.
infrastructure
Visual Studio Code
Once inside the network, the attackers used the tunneling feature of the Visual Studio Code development tool to create a hidden backdoor that allowed them to access the internal system from outside.
organisation
the Visual Studio Code
Once inside the network, the attackers used the tunneling feature of the Visual Studio Code development tool to create a hidden backdoor that allowed them to access the internal system from outside.
organisation
SharePoint
The attackers exploited the SharePoint vulnerability to install a web shell and extract the server's encryption key, then created fake malicious data that appeared to be signed by the normal request, allowing them to execute code remotely.
infrastructure
Macos
ENCFORGE is specifically built for the artificial intelligence (AI) infrastructure, scanning for nearly 180 file extensions spanning model checkpoints, vector databases, training datasets, and embedding indices, along with macOS-centric files like Keychain stores, Xcode project files, and Apple Pages and Numbers documents.
data_breach
180 file extensions
ENCFORGE is specifically built for the artificial intelligence (AI) infrastructure, scanning for nearly 180 file extensions spanning model checkpoints, vector databases, training datasets, and embedding indices, along with macOS-centric files like Keychain stores, Xcode project files, and Apple Pages and Numbers documents.
organisation
Delete Azure Resources
JADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete Azure Resources.
organisation
JADEPUFFER
The threat actor known as JADEPUFFER has been observed orchestrating destructive actions within a Microsoft Azure environment using compromised service principals.
organisation
Microsoft Azure
The threat actor known as JADEPUFFER has been observed orchestrating destructive actions within a Microsoft Azure environment using compromised service principals.
organisation
Microsoft
Microsoft, which is tracking the activity under the name
Storm-3168
, has called it an evolution of the threat actor's tradecraft.
organisation
SQL
"The destructive operations were facilitated by compromising service principals and targeted Azure Storage Accounts, SQL databases, Key Vaults, Function Apps, recovery protection locks, Virtual Machines, and App Services," researchers Yossi Weizman and Tushar Mudi, along with the Microsoft Security Research team,
said
.
organisation
Virtual Machines
"The destructive operations were facilitated by compromising service principals and targeted Azure Storage Accounts, SQL databases, Key Vaults, Function Apps, recovery protection locks, Virtual Machines, and App Services," researchers Yossi Weizman and Tushar Mudi, along with the Microsoft Security Research team,
said
.
organisation
App Services
"The destructive operations were facilitated by compromising service principals and targeted Azure Storage Accounts, SQL databases, Key Vaults, Function Apps, recovery protection locks, Virtual Machines, and App Services," researchers Yossi Weizman and Tushar Mudi, along with the Microsoft Security Research team,
said
.
organisation
the Microsoft Security Research
"The destructive operations were facilitated by compromising service principals and targeted Azure Storage Accounts, SQL databases, Key Vaults, Function Apps, recovery protection locks, Virtual Machines, and App Services," researchers Yossi Weizman and Tushar Mudi, along with the Microsoft Security Research team,
said
.
organisation
Azure Virtual Machines
The enumeration activity targeted Azure Virtual Machines, subscriptions, resource groups, and resources for close to 16 hours, carrying out over 300 read operations during the time period.
organisation
API
However, each of the database deletion attempts ended up in failure due to the use of an unsupported API version for the Azure SQL database resource type.
organisation
Storm-3168
Microsoft said it has also detected repeated probing from Storm-3168 linked infrastructure against several Azure App services for different customers, adding that the attacks are likely automated or scripted given the division of work using multiple service principals and the timing between the different operations.
Tactical Metrics
Metrics
infrastructure
Windows
Affected Product
Click for context!
The attackers specifically installed ransomware on the system volume (SYSVOL) in the Windows domain environment, where policies and files are shared.
Metrics
infrastructure
Visual Studio Code
Affected Product
Once inside the network, the attackers used the tunneling feature of the Visual Studio Code development tool to create a hidden backdoor that allowed them to access the internal system from outside.
Metrics
infrastructure
Macos
Affected Product
ENCFORGE is specifically built for the artificial intelligence (AI) infrastructure, scanning for nearly 180 file extensions spanning model checkpoints, vector databases, training datasets, and embedding indices, along with macOS-centric files like Keychain stores, Xcode project files, and Apple Pages and Numbers documents.
Metrics
data_breach
180
File Extensions
ENCFORGE is specifically built for the artificial intelligence (AI) infrastructure, scanning for nearly 180 file extensions spanning model checkpoints, vector databases, training datasets, and embedding indices, along with macOS-centric files like Keychain stores, Xcode project files, and Apple Pages and Numbers documents.
Intelligence Sources
The Hacker News
2026-09-28
Dailysecu
2026-10-04
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-07T09:22
Comprehensive Tactical Telemetry
Highly Correlated Entities
16x
organisation
Identified Entity
Secure Point
entity
3x
tactic
Cyber Operation Type
Ransomware
tactic
3x
infrastructure
Affected Product
Windows
software
3x
target region
Target Region
AFRICA
region
3x
attribution
Attributing Entity
Xcode
authority
2x
industry
Targeted Sector
Telecommunications
sector
2x
general metric
Systems
40
systems
2x
general metric
Hours
2
hours
2x
target region
Target Country
Portugal
country
Contextual Telemetry
Context Block
10 METRICS
source region
Origin Country
China
country
vulnerability
Exploited CVE
CVE-2025-3248
cve
tactic
MITRE ATT&CK Technique
T1555.001 - Keychain
technique
data breach
File Extensions
180
file extensions
timeline
Temporal Reference
early June 2026
date
general metric
Close Hours
16
close hours
general metric
Own Minutes
90
own minutes
general metric
Destructive Related Operations
150
destructive related operations
general metric
Minutes
35
minutes
general metric
Deletion Attempts
100
deletion attempts
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.