Cyber Threat Intel 4 min read

The Warlock Ransomware Group Still Breaks In Through SharePoint, Now at a Water Utility

Symantec says the China-linked group hit a water company, a telecom operator, a regional government and a university in two months, disabling security tools on 40 machines in about two hours.

Priya Nair
Data, AI Governance & Policy Analyst
Published 3 Oct 2026, 9:51 AM (SGT)
Share:
Open settling basins at a water treatment plant Open settling basins at a water treatment plant Photo by DengdaiFengQi on Pixabay
Advertisement

3 OCT 2026 — A year ago, the group behind Warlock ransomware broke into organisations through a chain of flaws in Microsoft's SharePoint server software, known as ToolShell, that had no patch at the time. One of them, CVE-2025-53770, lets an attacker run code on an on-premises SharePoint server over the network. Patches have long since shipped. New research from Symantec shows the same group still getting in through SharePoint, and in the past two months it has hit a water utility and a telecoms provider.

Symantec tracks the China-linked group as Longlegs; Microsoft calls it Storm-2603. The latest victims, at least four organisations, were in Portuguese- and Spanish-speaking countries across Europe, Africa and Latin America.

Who was hit

Besides the water utility and the telecoms provider, the victims were a regional government body and a university, according to Symantec's report. Symantec does not name them. It notes that Warlock has previously been used against organisations in the United States, Brazil, India, Russia, Taiwan and Japan, and that the recent concentration could be opportunistic, driven by exposed servers, or deliberate.

How one intrusion unfolded

In the attack Symantec describes in detail, the victim was a critical infrastructure operator and the first sign was a web shell planted on a SharePoint server on 22 July 2026. The attackers used it to steal the server's cryptographic machine keys, which let them forge signed requests that SharePoint would then run as code.

Over the following week they moved through the network. They added a disguised account to the administrators group on several machines, ran an open-source penetration-testing tool to map the domain and spray passwords, and installed Microsoft's own Visual Studio Code as a service to use its built-in tunnel for remote access. Because that tool is signed by Microsoft and relays through Microsoft's servers, its traffic can look like an ordinary developer's.

4+Organisations hit in the past two months, Symantec says
40+Machines where security software was disabled within about two hours
33+Machines then hit with Warlock ransomware
22–31 JulyFrom first web shell to ransomware in the intrusion Symantec traced

The final hours

Early on 31 July, the attackers pushed a tool that disables security software out to at least 40 machines within about two hours. In other recent attacks the group has done this by abusing K7RKScan, a signed but vulnerable driver, a technique known as bringing your own vulnerable driver. Warlock appeared on each machine almost as soon as its protection was switched off, reaching at least 33.

Advertisement

To spread the ransomware, the attackers placed it in the domain's SYSVOL share, a folder that is copied automatically to every domain controller. On three machines, Symantec found records showing the ransomware arriving through that ordinary replication, rather than being pushed to each one.

Why old flaws still work

Symantec says exploiting ToolShell and related SharePoint flaws remains a viable way into deployments that have not been patched or otherwise mitigated. Stolen machine keys are a particular risk because, as we reported in July, they can survive a patch unless they are rotated.

BleepingComputer notes that Microsoft observed state-backed groups and Storm-2603 using ToolShell exploits in 2025. Symantec has published file hashes and infrastructure linked to the attacks.

What defenders can check

Organisations running on-premises SharePoint can check that the ToolShell patches are installed, rotate the server's machine keys, and look for unexpected files in its LAYOUTS directory. Other signs from this campaign include Visual Studio Code tunnels running as a service on servers and executables appearing in SYSVOL's scripts folder.

Advertisement
Priya Nair
Data, AI Governance & Policy Analyst

Priya Nair covers AI governance, data protection, privacy, and digital trust topics for RECATOOLS.

View author profile → · Editorial policy

About this byline Priya Nair is a RECATOOLS editorial persona for AI governance, privacy, and digital trust coverage. Articles are produced and reviewed under RECATOOLS editorial supervision.

Corrections policy

Advertisement