Skip to content
TECH CEO Daily
CybersecuritySecurity Alert

Warlock ransomware hits water utility and telecom provider via SharePoint, Symantec says

Symantec and Carbon Black say a China-nexus group broke into at least four organizations through on-premises SharePoint, then disabled security tools and spread ransomware.

By · Editor

· 3 min read · Fact-checked

The 60-second brief

  • 1Symantec says Warlock ransomware hit a water utility, a telecom provider, a regional government body and a university.
  • 2The group, which Symantec calls Longlegs and Microsoft tracks as Storm-2603, entered through Microsoft SharePoint vulnerabilities.
  • 3In one intrusion, attackers disabled security tools on at least 40 hosts, then deployed ransomware on at least 33.

The news

A China-linked group used Warlock ransomware against a water utility, a telecommunications provider, a regional government body and a university after breaking in through Microsoft SharePoint flaws, Symantec and Carbon Black researchers said in an October 1, 2026, report.

Symantec, part of Broadcom (AVGO), says Warlock is developed by a China-nexus threat actor it calls Longlegs, also tracked as Storm-2603. The researchers said at least four organizations were hit in the past two months, in Portuguese- and Spanish-speaking countries across Europe, Africa and Latin America. The report does not name the victims or their countries.

The way in was on-premises SharePoint, Microsoft's (MSFT) document and intranet server. Symantec points to ToolShell, a chain of four SharePoint flaws, CVE-2025-49704, CVE-2025-49706, CVE-2025-53770 and CVE-2025-53771, exploited since mid-2025, and to other related SharePoint vulnerabilities. SecurityWeek reported that the group's arsenal may also include six 2026 flaws: CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, CVE-2026-58644, CVE-2026-50522 and CVE-2026-55040. The Record noted that the Cybersecurity and Infrastructure Security Agency (CISA) warned in July 2026 that hackers were exploiting six new SharePoint vulnerabilities.

Symantec described one intrusion step by step. It began on July 22, 2026, with a web shell, a hidden remote-control script, on a SharePoint server. Over the next week the attackers ran reconnaissance, used DLL sideloading to run code under legitimate programs, set up a Visual Studio Code tunnel for remote access, added a domain account to admin groups and used the NetExec tool to map Active Directory and try passwords.

Early on July 31, they pushed a tool that kills antivirus and endpoint detection software to at least 40 hosts within about two hours, according to the report. It abused a signed but vulnerable K7RKScan driver (CVE-2025-1055), a technique known as bring your own vulnerable driver. The attackers then staged Warlock in the domain's SYSVOL share, a folder that domain-joined Windows machines read for Group Policy settings, and ran it on at least 33 hosts.

The numbers

Organizations hit in the past two months (Symantec)
At least 4
Hosts where security tools were disabled, in about two hours
At least 40
Hosts hit with Warlock ransomware in one intrusion
At least 33
ToolShell SharePoint CVEs from 2025
4
2026 SharePoint flaws possibly in the group's arsenal (SecurityWeek)
6

Why CEOs should care

For CIOs and CISOs, this is a patch-debt story. Symantec's conclusion is that ToolShell and related SharePoint flaws remain a workable way in, more than a year after Warlock came to prominence, against servers that have not been patched or otherwise mitigated. Find every on-premises SharePoint server, confirm it carries current fixes, and ask why any of them face the internet. The Hacker News reported that the attackers collect ASP.NET machine keys, which let them forge signed requests the server trusts, so a server that sat exposed while unpatched may need its keys rotated, not just a patch.

For security operations teams, the timeline is the lesson. Attackers spent more than a week inside before switching off defenses on 40 hosts in roughly two hours. Alerts for new driver loads, Visual Studio Code tunnels on servers, unexpected additions to local Administrators groups and payloads staged in SYSVOL, all steps documented in the Symantec report, would each have offered a chance to stop the attack before encryption.

For boards and leaders at utilities, telecoms and public bodies, the victim list is the warning. Symantec said the presence of critical infrastructure operators shows the real-world consequences when ransomware succeeds against essential services. Ask whether recovery plans assume security tools can be disabled at scale, and whether operational systems are separated from the corporate network where SharePoint sits.

The bigger picture

Warlock sits where criminal and state activity blur. The Record reported that Microsoft has called the operators China-based hackers who used LockBit ransomware before switching to Warlock, but could not tie them to any Chinese state-backed group it tracks. Warlock was previously used against organizations in the US, Russia, Brazil, India, Taiwan and Japan, the outlet said. Separately, SecurityWeek recalled that Chinese state-sponsored groups Linen Typhoon and Violet Typhoon exploited ToolShell as zero-days in 2025, before public disclosure. Symantec said the recent focus on Portuguese- and Spanish-speaking countries may reflect opportunistic hunting for exposed servers or more deliberate tasking.

What’s next

Watch whether Symantec, Microsoft or CISA confirm Warlock exploitation of specific 2026 SharePoint flaws, whether any of the victims disclose the attacks, and whether the group turns back toward US targets. Organizations still running on-premises SharePoint should treat the next Microsoft security release as a test of how fast they can patch.

What “Fact-checked” means

Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.

What we checked
Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
How
A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
Who
The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, . A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
If something is wrong
“Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error

How we fact-check →

Companies in this story

WarlockMicrosoft SharePointSymantecRansomwareCritical infrastructure

Earlier coverage of Microsoft

All Microsoft coverage →

Written by

Editor · Technology & Business Writer

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

CoversAICybersecurityBig TechSaaSStartupsFintech

About this story. Researched from primary sources whenever they are available and fact-checked before publication.

Published by Tech CEO Daily, an independent publication. Masthead · Editorial standards

Follow Tech CEO Daily on Facebook for the day’s top stories in your feed.

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Monday to Saturday, 7 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.