Skip to content
Cybersecurity

Warlock Ransomware Explained: SharePoint Attacks (2026)

/ 11 min read / Malik Tanveer Dhool
← Back to Blog
Share X in

WarBrief Live | October 5, 2026 | Cybersecurity

A ransomware crew tracked as Warlock has spent the past two months breaking into critical infrastructure through one of the least exotic doors in enterprise IT: unpatched Microsoft SharePoint servers. According to new research from Symantec’s Threat Hunter Team, published October 1, 2026, the suspected China-linked group compromised at least four organizations — including a water utility and a telecommunications provider — by exploiting SharePoint vulnerabilities, some patched more than a year ago. This is the Warlock ransomware SharePoint campaign, explained: what happened, how the intrusion worked, who is behind it, and what defenders can do about it.

Key Takeaways

  • Symantec’s Threat Hunter Team reported on October 1, 2026 that Warlock — tracked as Longlegs by Symantec and Storm-2603 by Microsoft — hit at least four organizations in the past two months: a water utility, a telecom provider, a regional government body, and a university.
  • Victims were in Portuguese- and Spanish-speaking countries across Europe, Africa, and Latin America; initial access came through on-premises SharePoint vulnerabilities, including the 2025 “ToolShell” exploit chain.
  • In one documented intrusion, the attackers disabled endpoint protection on at least 40 machines within about two hours and deployed ransomware on at least 33, staging the payload in the domain’s SYSVOL share.
  • The China connection is a Symantec assessment, not a government attribution — and researchers warn that patching alone is not enough, because stolen SharePoint machine keys survive updates unless they are rotated.

What is Warlock ransomware?

Warlock is a ransomware operation: criminals break into a network, encrypt files — typically after stealing data first — and threaten to publish the stolen material on a leak site if the victim will not pay. The group emerged in June 2025, according to BleepingComputer, and gained notoriety a month later when attackers deploying it exploited a chain of zero-day vulnerabilities in Microsoft SharePoint known as ToolShell (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771).

Researchers track the same actor under several names: Symantec calls it Longlegs and attributes the development of the Warlock ransomware to the group, while Microsoft tracks it as Storm-2603. It is also known as Gold Salem. Symantec says the operation overlaps with older activity clusters known as CL-CRI-1040, CamoFei, and ChamelGang. Earlier analysis noted code patterns reminiscent of the leaked LockBit 3.0 builder, suggesting Warlock may be a customized derivative of that toolkit rather than an entirely original creation — a common pattern in the ransomware economy.

Warlock’s trajectory mirrors the broader industrialization of digital extortion. For the bigger picture on how these operations are organized, read our explainer on the ransomware-as-a-service model that powered the KillSec takedown.

What happened in the October 2026 attacks?

The latest campaign came to light when Symantec and Carbon Black’s Threat Hunter Team published their findings in a blog post on Thursday, October 1, 2026, with BleepingComputer covering the report on October 2. Over roughly the preceding two months, the group targeted at least four organizations: a water utility, a telecommunications provider, a regional government body, and a university. The victims were located in Portuguese- and Spanish-speaking countries spanning Europe, Africa, and Latin America.

“In the past two months, Longlegs has attacked at least four organizations, including two critical infrastructure operators (a water utility and a telecommunications provider), a regional government body, and a university,” the Broadcom-owned cybersecurity unit said, as reported by The Hacker News. “Victims were in Portuguese- and Spanish-speaking countries, spanning Europe, Africa, and Latin America.”

The researchers stressed that the ToolShell flaws — patched in July 2025 — likely remain in the group’s arsenal alongside newer SharePoint vulnerabilities that the U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned about in an advisory published in July 2026. More than a year after Warlock first emerged exploiting SharePoint flaws, those same flaws are still producing victims.

Compromised on-premises server racks with a cracked security shield, illustrating how Warlock ransomware breached SharePoint
AI-generated illustration

The Warlock ransomware SharePoint attack chain, explained

The intrusion Symantec documented in detail began on July 22, 2026 and unfolded over nine days — a timeline that shows how methodically modern ransomware crews work once they are inside. Here is the chain, step by step.

1. The front door: SharePoint exploitation. The attackers gained initial access by exploiting vulnerabilities in on-premises Microsoft SharePoint deployments, then dropped a web shell designed to work across multiple SharePoint versions. The shell was placed in the SharePoint LAYOUTS directory — a location the attackers could reach without file-upload permissions.

2. Stealing the keys to the kingdom. Once inside, the attackers collected ASP.NET machine keys from the SharePoint configuration and used them to forge a signed payload that enabled remote code execution inside the SharePoint application pool. This is the detail that makes the campaign especially dangerous: machine keys survive patching, so updating SharePoint without rotating the keys leaves the back door open.

3. Quiet expansion. Two days after gaining access, the intruders moved to reconnaissance, using the open-source penetration-testing framework NetExec for Active Directory enumeration, credential spraying, and remote command execution. They installed the main executable of Visual Studio Code Insiders as a service, using VS Code’s built-in tunneling capability to maintain remote access to compromised machines — legitimate software turned into a command-and-control channel.

4. Blinding the defenders. Before triggering encryption, the attackers pushed a tool designed to disable security software to at least 40 hosts within about two hours, using the bring-your-own-vulnerable-driver (BYOVD) technique: a legitimately signed K7RKScan driver, vulnerable to CVE-2025-1055, loaded at kernel level and used to terminate antivirus and endpoint-detection processes.

5. Mass deployment. The ransomware payload was staged in the domain’s SYSVOL share — the network location replicated across every domain controller — so ordinary domain replication delivered it to machines across the network. Warlock then deployed on at least 33 hosts, with the final stage of the attack occurring on July 31.

By the numbers: what is confirmed vs. reported

Metric Figure Source
Organizations hit in this campaign At least 4 (water utility, telecom, regional government, university) Symantec — CONFIRMED (via BleepingComputer, The Hacker News)
Hosts with security software disabled At least 40, within about two hours (single intrusion) Symantec — CONFIRMED
Hosts where Warlock ransomware deployed At least 33 (single intrusion) Symantec — CONFIRMED
CVEs in the 2025 ToolShell chain 4: CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, CVE-2025-53771 Microsoft / CISA — CONFIRMED
Time from initial access to full encryption (documented case) 9 days (July 22 to July 31, 2026) BleepingComputer — CONFIRMED
New victims named on Warlock’s leak site in the last 30 days 0 ThreatVectr tracking — REPORTED (single source)

Figures marked CONFIRMED appear in two or more independent reports; REPORTED figures come from a single source’s tracking and should be treated as provisional. The attribution of the group to China is a vendor assessment, not a government finding.

Network diagram of the Warlock ransomware attack chain spreading from a compromised central server to connected devices
AI-generated illustration

Who is behind Warlock — and is China really involved?

Symantec assesses that the operator behind Warlock has links to China, describing it as a China-nexus or China-linked group. That assessment is based on tooling overlaps and infrastructure analysis — it is not a public attribution by any government, and researchers have been careful with the claim. Threat-intelligence analysts tracking the campaign describe the China connection as medium confidence, noting that tooling overlaps with activity other vendors track under different names, and that single-source attribution rarely holds.

It is also worth separating Warlock from other users of the same exploits. Microsoft observed that by August 2026, the state-backed hacking groups Linen Typhoon and Violet Typhoon were also using ToolShell exploits in their attacks — but those are distinct, state-backed actors, not the Warlock ransomware crew. The same front door can serve very different intruders.

The group’s history reinforces the picture of an adaptable, financially motivated operation rather than a one-shot campaign: earlier in 2026 it was linked to the compromise of SmarterTools through an unpatched SmarterMail instance, and its operators have relied on legitimate tools such as Velociraptor for command and control.

Background and timeline

  • June 2025: Warlock ransomware emerges; researchers first spot it on underground forums shortly after SharePoint authentication and deserialization flaws are disclosed.
  • July 2025: Attackers deploying Warlock exploit the ToolShell zero-days in Microsoft SharePoint (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, CVE-2025-53771), bringing the group to prominence.
  • Early 2026: The group is linked to the compromise of software vendor SmarterTools via an unpatched SmarterMail instance, showing its pivot to supply-chain-style targets.
  • July 22, 2026: Initial access in the intrusion Symantec would later document in detail — a cross-version SharePoint web shell is dropped, followed by reconnaissance and staging.
  • July 31, 2026: Final stage of that intrusion: security software disabled on 40+ hosts, Warlock deployed on at least 33.
  • October 1, 2026: Symantec and Carbon Black’s Threat Hunter Team publishes its report on the campaign against critical infrastructure, government, and education targets.
  • October 2–3, 2026: BleepingComputer and The Hacker News report the findings, and industrial-security outlets flag the implications for utilities and telecom operators.

Why water utilities and telecoms?

Utilities and telecom providers sit at the intersection of two attacker incentives: they are essential services, so disruption creates maximum pressure to pay, and they often run sprawling, legacy IT estates — including internet-facing on-premises software like SharePoint — with security budgets that lag behind their operational importance. A water utility’s billing and control networks may share infrastructure, and a single compromised document server can become a bridgehead into the wider corporate network.

The timing is notable. WarBrief recently reported on a suspected Iranian hacking campaign against US water and energy grids — a different actor with different motives, but the same target set. And attacks on civilian infrastructure have become a standard feature of modern conflict, as documented in our analysis of cyber warfare in the Russia-Ukraine conflict. Whether the motive is extortion, espionage, or pre-positioning for a future crisis, the water sector’s digital perimeter keeps proving to be the softest point.

What this means for US/UK/EU readers

For most readers, the direct risk is organizational, not personal: if your employer, school, or local utility runs an on-premises SharePoint Server that faces the internet, this campaign is aimed at exactly that footprint. In the UK, water and telecom operators carry security duties under the NIS Regulations for operators of essential services; in the US, CISA has repeatedly flagged SharePoint flaws in its advisories and its Known Exploited Vulnerabilities catalogue.

The practical defenses, per Microsoft, CISA, and the UK’s National Cyber Security Centre guidance on this exploit family, are: patch SharePoint immediately; rotate the farm’s ASP.NET machine keys after patching (patching alone does not evict an attacker who already stole them); hunt for leftover web shells and anomalous VS Code tunneling before rotating keys, so a surviving shell cannot steal the new ones; and segment operational networks from corporate IT so a compromised document server cannot reach control systems. For households, the downstream risk is service disruption — the same reason utilities are attractive targets — which is worth a passing thought the next time a provider announces “system maintenance.”

Different perspectives

The researchers’ view is blunt: ToolShell and other SharePoint vulnerabilities remain viable initial-access vectors more than a year after Warlock first emerged exploiting them, and the campaign is ongoing. Symantec’s report includes indicators of compromise for defenders to hunt with, signaling that the team expects more victims to surface.

Independent trackers urge caution on two fronts. First, attribution: the China link is assessed at medium confidence, and the absence of government attribution means the question of state direction versus criminal opportunism remains open. Second, tempo: no new victims have appeared on Warlock’s leak site in the last 30 days, which could mean a lull, a quiet rebrand, or negotiations happening without public pressure — none of which is reassuring.

The defender community’s takeaway is architectural rather than tactical. The campaign’s most unsettling lesson is not any single exploit but the key-theft detail: a patch that does not rotate stolen credentials is a patch that changes nothing. Security teams are treating the episode as a reminder that incident response for these intrusions must assume the attacker already holds the keys — literally.

What to watch next

Three things will show where this campaign goes. First, whether CISA or European agencies issue fresh alerts or add new SharePoint CVEs to their exploited-vulnerabilities catalogues — that would signal the group has moved beyond the ToolShell-era flaws. Second, whether new names appear on Warlock’s leak site, which would indicate the quiet period is over. Third, whether the geographic focus widens beyond Portuguese- and Spanish-speaking countries; the tooling is not region-locked, and nothing in the attack chain is specific to those networks. Follow WarBrief’s intelligence desk for updates as the picture develops.

Frequently asked questions

What is Warlock ransomware?
Warlock is a ransomware operation that emerged in June 2025 and rose to prominence by exploiting Microsoft SharePoint vulnerabilities. Its operators break into networks, steal data, encrypt files, and threaten to publish the stolen material unless a ransom is paid. Symantec tracks the group as Longlegs; Microsoft tracks it as Storm-2603.

How did Warlock breach SharePoint servers?
The attackers exploited vulnerabilities in on-premises SharePoint Server — including the 2025 ToolShell chain and newer flaws — to drop cross-version web shells. They then stole ASP.NET machine keys to forge signed payloads for remote code execution, used legitimate tools like NetExec and VS Code tunnels to expand access, disabled endpoint protection with a vulnerable signed driver, and deployed ransomware across the network via the domain’s SYSVOL share.

Is Warlock linked to China?
Symantec assesses that the group behind Warlock has links to China, based on tooling and infrastructure analysis. However, this is a vendor assessment at medium confidence — no government has publicly attributed the campaign to China, and researchers caution against treating it as a confirmed state operation.

How can organizations defend against Warlock?
Patch on-premises SharePoint immediately, then rotate the farm’s ASP.NET machine keys — patching alone will not evict an attacker who already stole them. Hunt for leftover web shells and anomalous remote-access tooling before rotating keys, keep internet-facing servers segmented from operational networks, and monitor for the campaign’s indicators of compromise published by Symantec.

Why does Warlock target water utilities and telecoms?
Essential-service operators face maximum pressure to restore operations quickly, which makes them attractive extortion targets, and they often run legacy, internet-facing IT systems with limited security resources. The same logic has drawn other actors — including suspected state-backed intruders — to the water and energy sectors.

Sources

Written by

Malik Tanveer Dhool

Defense and intelligence analysis for WarBrief.live. Covering conflict, technology, and geopolitical strategy.