Warlock ransomware gang breaches water, telecom and government networks via SharePoint flaws
Symantec and Carbon Black researchers say the China-linked Warlock group, also tracked as Longlegs, has compromised a water utility, a telecom provider, a regional government body and a university by exploiting on-premises SharePoint vulnerabilities, including the ToolShell exploit chain. In one July 22 intrusion, the attacker disabled security software on roughly 40 hosts within two hours and deployed Warlock ransomware to at least 33 machines, using a signed but vulnerable driver to kill endpoint defenses.
GoKawiil's interpretation of the reporting above, not reported fact.
The targeting pattern researchers describe—concentrated on Portuguese- and Spanish-speaking countries across Europe, Africa and Latin America—suggests a deliberate regional focus that could leave critical infrastructure operators in those areas particularly exposed. The group's reuse of nation-state-linked SharePoint exploits also shows how quickly commodity ransomware actors can weaponize vulnerabilities first seen in state-sponsored campaigns, potentially widening the pool of organizations at risk.
- Warlock/Longlegs exploited SharePoint flaws, including the ToolShell chain, to breach critical sectors like water and telecom.
- Attackers used a vulnerable signed driver (BYOVD technique) to disable security tools on dozens of hosts before deploying ransomware.
- Targeting has concentrated on Portuguese- and Spanish-speaking regions in Europe, Africa, and Latin America over the past two months.
YubiKey 5 Series Security Key — With ransomware gangs like Warlock exploiting SharePoint flaws to breach critical infrastructure, hardening authentication is essential. A hardware security key like the YubiKey adds a strong phishing-resistant layer of protection for admin and remote access accounts that attackers often target first. It's a simple, practical step individuals and IT teams can take to reduce the risk of credential-based intrusions.
See YubiKey 5 Series Security Key on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.Source: bleepingcomputer.com, 2026-10-02
Published there as: “Warlock ransomware breach SharePoint in water, telecom operator attacks”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.