Warlock Ransomware Hits Water And Telecom Firms Via SharePoint
A China-linked ransomware operation known as Warlock has breached a water utility, a telecommunications provider, a regional government body, and a university. The attackers gained initial access to each network by exploiting vulnerabilities in on-premises Microsoft SharePoint servers, a tactic the group still favors.

Symantec and Carbon Black researchers documented the campaign, which targeted Portuguese-speaking and Spanish-speaking countries across Europe, Africa, and Latin America over the past two months. The findings show that SharePoint flaws, including the notorious ToolShell exploit chain, remain a viable entry point more than a year after their discovery.
The inclusion of two critical infrastructure operators among the victims highlights the real-world damage that ransomware can inflict on essential public services. Water utilities and telecom providers support large populations every day, so a successful attack against either sector can disrupt communities far beyond the victim's network. This article examines how the group operates, how it deploys ransomware across entire domains, and what SharePoint administrators can do to block similar intrusions.
Symantec tracks the threat actor as Longlegs, while Microsoft follows the same group as Storm-2603, and researchers describe it as a China-nexus operation. Symantec also ties Longlegs to older activity clusters known as CL-CRI-1040, CamoFei, and ChamelGang, and it credits the group with developing Warlock itself. The ransomware first surfaced in June 2025 and drew widespread attention one month later, when its operators began exploiting the SharePoint zero-days dubbed ToolShell.
Earlier Warlock attacks hit organizations in the United States, Brazil, India, Russia, Taiwan, and Japan, so the recent regional focus marks a notable shift. Symantec suggests that the narrower targeting may reflect opportunistic scanning for exposed SharePoint servers, although it does not rule out a more deliberate tasking. Researchers have not named the affected organizations or the specific countries involved, which leaves the full scope of the campaign unclear for now.
In May 2025, Viettel Cyber Security researchers chained two SharePoint flaws, CVE-2025-49706 and CVE-2025-49704, to achieve remote code execution at Pwn2Own Berlin. Microsoft patched both bugs in its July 2025 Patch Tuesday release, but threat actors quickly developed new exploits that bypassed those initial fixes.
Microsoft assigned the bypasses CVE-2025-53770 and CVE-2025-53771, and attackers exploited them as zero-days starting no later than July 18, 2025. Dutch firm Eye Security spotted the first attacks and later counted more than 85 compromised servers belonging to 54 organizations worldwide.
Microsoft confirmed in its advisory that the flaws affected only on-premises deployments, stating that "SharePoint Online in Microsoft 365 is not impacted." The company later released emergency updates for SharePoint Server 2016, SharePoint Server 2019, and SharePoint Subscription Edition to close both zero-day holes.
CISA added CVE-2025-53770 to its Known Exploited Vulnerabilities catalog, and in July 2026, the agency urged organizations to harden SharePoint against newer exploitation. Symantec believes Longlegs still keeps the ToolShell exploits in its arsenal, alongside more recent SharePoint flaws that CISA flagged in that advisory.
After exploiting SharePoint, Longlegs drops a web shell into the LAYOUTS directory for several SharePoint versions at once, ensuring it works on any installation. The web shell harvests the farm's ASP.NET machine keys, which the attackers then use to forge signed payloads that execute code inside SharePoint.
This technique mirrors the original ToolShell attacks, in which intruders stole validation keys and crafted malicious ViewState data that the server trusted and deserialized. Once inside, the group relies on a toolkit that blends legitimate software with stealthy evasion methods, and the most notable techniques include the following:
- DLL sideloading: Longlegs pairs legitimate executables with malicious DLL files, allowing it to load harmful code into memory under the cover of trusted processes.
- Cloud-hosted payloads: The group downloads follow-on tools from legitimate file-sharing services such as Catbox and Wasabi, which helps its traffic blend with normal activity.
- BYOVD attacks: Longlegs abuses K7RKScan, a signed but vulnerable driver tracked as CVE-2025-1055, to terminate protected security processes at the kernel level.
- Living-off-the-land tools: The attackers run built-in Windows utilities such as net, whoami, and nltest to quietly map users, domains, and trust relationships.
- VS Code tunnels: Longlegs installs the Microsoft-signed Visual Studio Code Insiders binary as a service, then uses its built-in tunnel feature for covert remote access.
Because Microsoft signs the VS Code binary and relays tunnel traffic through its own infrastructure, the connections resemble ordinary activity from developer workstations. This approach allows the attackers to avoid custom remote access trojans, which security products often detect, while keeping a persistent channel into the network. Defenders should therefore treat unexpected VS Code tunnel services on servers as a strong warning sign rather than routine developer behavior.
Inside the Critical Infrastructure Intrusion
Symantec reconstructed an attack against a critical infrastructure operator that began on July 22, 2026, when intruders planted a web shell on SharePoint. Two days later, the attackers ran reconnaissance commands on a second SharePoint host and deleted files that appeared to be early staging artifacts.
On July 27, a compromised host contacted a Burp Collaborator domain, a step consistent with a scanning tool confirming that injected code had executed successfully. The core exploitation phase started on July 28, when the attackers loaded a deserialization gadget and achieved code execution inside the SharePoint application pool.
Within 90 minutes, the intruders pulled three separate installer packages from two public hosting services, suggesting they had several payloads ready to deploy. On July 28 and 29, they added a domain account named SPSEPRDSetup to local administrator groups, likely mimicking the naming of legitimate SharePoint service accounts. The attackers also ran NetExec, the successor to CrackMapExec, for Active Directory enumeration, credential spraying, and remote command execution across the domain.
The final phase started early on July 31, when the attackers pushed an AV/EDR killer named a.exe from an internal network share to multiple hosts. According to Symantec, the tool disabled protection on "at least 40 hosts within about two hours," covering almost the entire environment.
Warlock surfaced on each machine moments after its defenses went down, and the ransomware ultimately reached at least 33 hosts across the organization. The attackers dropped two binaries, run.exe and rune.exe, along with a ransom note named how to restore your files.txt on every affected system.
To spread the payload, Longlegs staged it in the domain's SYSVOL share, which Windows automatically replicates to every domain controller and exposes domain-wide. This method lets attackers trigger execution through logon scripts or Group Policy objects, reaching the whole network at once instead of host by host. Telemetry from three hosts showed the Distributed File System Replication service delivering run.exe and rune.exe, which confirms that ordinary replication spread the ransomware.
Share:
Karolis Liucveikis
Experienced software engineer, passionate about behavioral analysis of malicious apps
Author and general operator of PCrisk's News and Removal Guides section. Co-researcher working alongside Tomas to discover the latest threats and global trends in the cyber security world. Karolis has experience of over 8 years working in this branch. He attended Kaunas University of Technology and graduated with a degree in Software Development in 2017. Extremely passionate about technical aspects and behavior of various malicious applications.
PCrisk security portal is brought by a company RCS LT.
Joined forces of security researchers help educate computer users about the latest online security threats. More information about the company RCS LT.
Our malware removal guides are free. However, if you want to support us you can send us a donation.
DonatePCrisk security portal is brought by a company RCS LT.
Joined forces of security researchers help educate computer users about the latest online security threats. More information about the company RCS LT.
Our malware removal guides are free. However, if you want to support us you can send us a donation.
Donate
▼ Show Discussion