Warlock ransomware keeps exploiting SharePoint flaws to hit water, telecom and government targets
TLDR
- Symantec reports the China-based Warlock ransomware operator, tracked as Storm-2603 and Longlegs, has hit at least four new victims over the past two months by exploiting Microsoft SharePoint flaws: a water utility, a telecommunications provider, a regional government body and a university.
- The victims are concentrated in Portuguese- and Spanish-speaking countries across Europe, Africa and Latin America.
- In one intrusion starting 22 July, the attacker deployed a tool that disabled security software on at least 40 hosts within about two hours, then launched Warlock ransomware on at least 33 of them.
- Warlock has exploited SharePoint vulnerabilities, including the ToolShell zero-day chain, since the group emerged in mid-2025, and Symantec says unpatched SharePoint deployments remain a viable way in more than a year later.
Storm-2603 gained notoriety in mid-2025 after exploiting a chain of SharePoint zero-days known as ToolShell (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770 and CVE-2025-53771), compromising more than 400 servers within weeks of disclosure alongside state-backed groups Linen Typhoon and Violet Typhoon.1 Symantec's latest report says the group's arsenal now may also include newer SharePoint flaws CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, CVE-2026-58644, CVE-2026-50522 and CVE-2026-55040.1
In the 22 July intrusion, the attacker drops a web shell designed to work across multiple SharePoint versions, then uses a signed but vulnerable K7RKScan driver via the bring-your-own-vulnerable-driver technique to disable antivirus and EDR tools on dozens of hosts before deploying ransomware.2 The attacker also installed Visual Studio Code Insiders as a service to abuse its built-in tunnelling feature for covert remote access that blends in with developer or administrator traffic, and used the open-source NetExec framework for Active Directory enumeration, credential spraying and remote command execution.1 The Warlock payload itself was staged inside the domain's SYSVOL share, a location replicated to every domain controller, letting the ransomware push out to the entire network via logon scripts or Group Policy rather than host by host.2
Two days after gaining initial access on 22 July, the attacker conducted reconnaissance and deleted staging artifacts, with Warlock appearing on each host "almost as soon as protection was disabled," before the ransomware's final deployment on 31 July.2 Symantec and Carbon Black's report includes indicators of compromise for the files and infrastructure used in the attacks.2
Why it matters: more than a year after ToolShell first put SharePoint zero-days on every defender's radar, Warlock is still finding unpatched on-premises SharePoint servers to break into, this time working through water and telecoms operators where a ransomware outage carries consequences well beyond one company's bottom line.