INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

China-linked ransomware attacks breach Secure Point in Seoul infrastructure

| 2026-10-04 11:53 CRITICAL HIGH RANSOMWARE & EXTORTION STATE-SPONSORED & ESPIONAGE
Executive Summary
AI-generated
A Chinese-linked attack group, identified as 'Longlegs' or 'Storm-2603', has been targeting at least four institutions in countries that use Portuguese and Spanish languages, primarily in Europe and Africa, and South America over the past two months. The attackers exploited a vulnerability in Microsoft SharePoint servers to breach critical infrastructure, including water and telecommunications companies, local government agencies, and universities. They used the tunneling feature of Visual Studio Code development tool to create a hidden backdoor that allowed them to access internal systems from outside, and installed ransomware on at least 33 systems, specifically targeting system volume (SYSVOL) in Windows domain environments. The attackers deployed 'Warlock' ransomware on a large scale after disabling security products, including antivirus, endpoint detection and response systems, and executing a disable tool on at least 40 systems for 2 hours.
Technical Mitigations AI-generated
• Apply the vendor fix for CVE-2025-3248 and treat internet-facing systems that were not patched in time as potentially compromised until verified.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2025-3248CVE-2025-3248
Target & Sectors
LATAM LATAM EUROPE EUROPE AFRICA AFRICA educationeducation governmentgovernment telecommunicationstelecommunications
Incident Timeline
‎early June 2026
Threat actors used an unspecified ransomware strain to breach Secure Point's systems in early June 2026, targeting key infrastructure and telecommunications in Seoul.
general_metric 18 hours
‎2026/10/04
China-linked ransomware attacks breached Secure Point, targeting key infrastructure in Seoul and telecommunications.
organisation Secure Point
organisation Microsoft SharePoint
organisation Storm-2603
infrastructure Windows
infrastructure Visual Studio Code
organisation the Visual Studio Code
organisation SharePoint
infrastructure Macos
data_breach 180 file extensions
organisation Delete Azure Resources
organisation JADEPUFFER
organisation Microsoft Azure
organisation Microsoft
organisation SQL
organisation Virtual Machines
organisation App Services
organisation the Microsoft Security Research
organisation Azure Virtual Machines
organisation API
organisation Storm-3168
Tactical Metrics
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
‎Visual Studio Code
Affected Product
Metrics
infrastructure
‎Macos
Affected Product
Metrics
data_breach
180
File Extensions