Warlock ransomware hits water and telecom operators via unpatched SharePoint servers
Symantec says the China-nexus group behind Warlock breached a water utility, a telecom provider, a regional government body and a university through SharePoint flaws.
At a glance
- Symantec attributes the attacks to Longlegs (Storm-2603), the China-nexus group behind Warlock ransomware.
- At least four organizations in Portuguese- and Spanish-speaking countries were hit in the past two months.
- Initial access came via on-premises SharePoint flaws, including the ToolShell chain.
- Attackers staged ransomware in the SYSVOL share and abused a vulnerable K7 driver to disable security tools.
The group behind the Warlock ransomware has attacked at least four organizations over the past two months, including a water utility and a telecommunications provider, by exploiting vulnerabilities in on-premises Microsoft SharePoint servers, according to a report published on October 1 by Symantec's threat intelligence team. The other victims were a regional government body and a university, all located in Portuguese- and Spanish-speaking countries across Europe, Africa and Latin America. The findings show that SharePoint flaws patched more than a year ago remain a viable entry point into critical infrastructure.
What happened
Symantec attributes the activity to a China-nexus actor it tracks as Longlegs, also known as Storm-2603, which it links to clusters previously reported as CL-CRI-1040, CamoFei and ChamelGang. Warlock first gained attention after the group exploited the SharePoint "ToolShell" chain in 2025. According to Symantec, the attackers continue to favor SharePoint-related bugs for initial access, including CVE-2025-49704, CVE-2025-49706, CVE-2025-53770 and CVE-2025-53771. SecurityWeek reports that the group has also exploited newer SharePoint vulnerabilities flagged by CISA, and quotes Symantec as saying the activity shows that ToolShell and related flaws remain a viable initial access route.
Technical details
According to Symantec, after gaining a foothold the attackers used DLL sideloading with payloads hosted on legitimate cloud services such as catbox.moe and wasabisys.com. They abused the remote tunneling feature in Visual Studio Code for covert access and used the NetExec tool for Active Directory enumeration and password spraying. To blind defenses, the group relied on a bring-your-own-vulnerable-driver technique using the K7 K7RKScan driver, tracked as CVE-2025-1055.
A notable step, Symantec says, was staging the ransomware payload inside the domain's SYSVOL share. Because SYSVOL is replicated to every domain controller, the researchers note this is a known way to push a payload to an entire network through a logon script or Group Policy object.
Who is affected
The confirmed victims are concentrated in Portuguese- and Spanish-speaking regions, but the techniques apply to any organization that still runs exposed, unpatched on-premises SharePoint. Water and telecom operators, government bodies and universities are the sectors named in the report.
What to do
Organizations should confirm that all SharePoint security updates are installed and, where ToolShell exposure was possible, rotate ASP.NET machine keys, since SecurityWeek notes the group has stolen them. Defenders should monitor for unexpected Visual Studio Code tunnels, new or modified files in SYSVOL and Group Policy objects, NetExec activity, and the loading of the vulnerable K7 driver. Blocking known-vulnerable drivers and restricting outbound connections to file-sharing services can further reduce the attack surface.
Related CVEs
Sources
- Warlock Ransomware Attackers Hit Water and Telecom Operators — Symantec Threat Hunter Team
- Warlock Expands SharePoint Exploitation in Critical Infrastructure Attacks — SecurityWeek
This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.



