The Warlock operator is the ChamelGang espionage group
Assessment
Symantec ties Longlegs back to older activity clusters it tracks as CL-CRI-1040, CamoFei and ChamelGang, the last associated with espionage, which SecurityAffairs relayed. This is Symantec's own assessment and is directly contradicted by Microsoft, which states it has not identified links between Storm-2603 and other known Chinese threat actors. The link is reportable as an assessment but is a live conflict between two first-party researchers, not consensus.
Where this claim appeared
Security Affairs · 2026-10-04
https://securityaffairs.com/200304/malware/warlock-ransomware-still-exploits-year-old-sharepoint-flaws-to-hit-critical-infrastructure.htmlWhat “Assessed, Not Confirmed” means
A named source states this as its own assessment, at its own stated confidence, rather than as established fact. Attribution to a nation state usually sits here. The assessment is real and reportable; treating it as settled is the error.
4 of 5 · rating scale
Assessed in
Warlock ransomware exploits SharePoint ToolShell flaws to hit water, telecom and government targetsThink this assessment is wrong? Report an error.