The news
A China-linked group used Warlock ransomware against a water utility, a telecommunications provider, a regional government body and a university after breaking in through Microsoft SharePoint flaws, Symantec and Carbon Black researchers said in an October 1, 2026, report.
Symantec, part of Broadcom (AVGO), says Warlock is developed by a China-nexus threat actor it calls Longlegs, also tracked as Storm-2603. The researchers said at least four organizations were hit in the past two months, in Portuguese- and Spanish-speaking countries across Europe, Africa and Latin America. The report does not name the victims or their countries.
The way in was on-premises SharePoint, Microsoft's (MSFT) document and intranet server. Symantec points to ToolShell, a chain of four SharePoint flaws, CVE-2025-49704, CVE-2025-49706, CVE-2025-53770 and CVE-2025-53771, exploited since mid-2025, and to other related SharePoint vulnerabilities. SecurityWeek reported that the group's arsenal may also include six 2026 flaws: CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, CVE-2026-58644, CVE-2026-50522 and CVE-2026-55040. The Record noted that the Cybersecurity and Infrastructure Security Agency (CISA) warned in July 2026 that hackers were exploiting six new SharePoint vulnerabilities.
Symantec described one intrusion step by step. It began on July 22, 2026, with a web shell, a hidden remote-control script, on a SharePoint server. Over the next week the attackers ran reconnaissance, used DLL sideloading to run code under legitimate programs, set up a Visual Studio Code tunnel for remote access, added a domain account to admin groups and used the NetExec tool to map Active Directory and try passwords.
Early on July 31, they pushed a tool that kills antivirus and endpoint detection software to at least 40 hosts within about two hours, according to the report. It abused a signed but vulnerable K7RKScan driver (CVE-2025-1055), a technique known as bring your own vulnerable driver. The attackers then staged Warlock in the domain's SYSVOL share, a folder that domain-joined Windows machines read for Group Policy settings, and ran it on at least 33 hosts.
The numbers
- Organizations hit in the past two months (Symantec)
- At least 4
- Hosts where security tools were disabled, in about two hours
- At least 40
- Hosts hit with Warlock ransomware in one intrusion
- At least 33
- ToolShell SharePoint CVEs from 2025
- 4
- 2026 SharePoint flaws possibly in the group's arsenal (SecurityWeek)
- 6
Why CEOs should care
For CIOs and CISOs, this is a patch-debt story. Symantec's conclusion is that ToolShell and related SharePoint flaws remain a workable way in, more than a year after Warlock came to prominence, against servers that have not been patched or otherwise mitigated. Find every on-premises SharePoint server, confirm it carries current fixes, and ask why any of them face the internet. The Hacker News reported that the attackers collect ASP.NET machine keys, which let them forge signed requests the server trusts, so a server that sat exposed while unpatched may need its keys rotated, not just a patch.
For security operations teams, the timeline is the lesson. Attackers spent more than a week inside before switching off defenses on 40 hosts in roughly two hours. Alerts for new driver loads, Visual Studio Code tunnels on servers, unexpected additions to local Administrators groups and payloads staged in SYSVOL, all steps documented in the Symantec report, would each have offered a chance to stop the attack before encryption.
For boards and leaders at utilities, telecoms and public bodies, the victim list is the warning. Symantec said the presence of critical infrastructure operators shows the real-world consequences when ransomware succeeds against essential services. Ask whether recovery plans assume security tools can be disabled at scale, and whether operational systems are separated from the corporate network where SharePoint sits.
The bigger picture
Warlock sits where criminal and state activity blur. The Record reported that Microsoft has called the operators China-based hackers who used LockBit ransomware before switching to Warlock, but could not tie them to any Chinese state-backed group it tracks. Warlock was previously used against organizations in the US, Russia, Brazil, India, Taiwan and Japan, the outlet said. Separately, SecurityWeek recalled that Chinese state-sponsored groups Linen Typhoon and Violet Typhoon exploited ToolShell as zero-days in 2025, before public disclosure. Symantec said the recent focus on Portuguese- and Spanish-speaking countries may reflect opportunistic hunting for exposed servers or more deliberate tasking.
What’s next
Watch whether Symantec, Microsoft or CISA confirm Warlock exploitation of specific 2026 SharePoint flaws, whether any of the victims disclose the attacks, and whether the group turns back toward US targets. Organizations still running on-premises SharePoint should treat the next Microsoft security release as a test of how fast they can patch.
What “Fact-checked” means
Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.
- What we checked
- Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
- How
- A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
- Who
- The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, Hussein Mukhtar. A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
- If something is wrong
- “Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error
Companies in this story








