ThreatPaper
Assessed, Not Confirmed

The Warlock operator is the ChamelGang espionage group

Assessment

Symantec ties Longlegs back to older activity clusters it tracks as CL-CRI-1040, CamoFei and ChamelGang, the last associated with espionage, which SecurityAffairs relayed. This is Symantec's own assessment and is directly contradicted by Microsoft, which states it has not identified links between Storm-2603 and other known Chinese threat actors. The link is reportable as an assessment but is a live conflict between two first-party researchers, not consensus.

Where this claim appeared

Security Affairs · 2026-10-04

https://securityaffairs.com/200304/malware/warlock-ransomware-still-exploits-year-old-sharepoint-flaws-to-hit-critical-infrastructure.html

What “Assessed, Not Confirmed” means

A named source states this as its own assessment, at its own stated confidence, rather than as established fact. Attribution to a nation state usually sits here. The assessment is real and reportable; treating it as settled is the error.

4 of 5 · rating scale

Assessed in

Warlock ransomware exploits SharePoint ToolShell flaws to hit water, telecom and government targets

Think this assessment is wrong? Report an error.