Published by Emerging Technologies Laboratory · via ETL Newswire
Security· 

China-Nexus Warlock Ransomware Hits Water Utility and Telecom via SharePoint Flaws

Symantec's Threat Hunter Team links the Longlegs group to fresh critical-infrastructure intrusions across Europe, Africa, and Latin America, all riding the same on-premises SharePoint exploit chain flagged by CISA in July.

By Renée Kovac, Correspondent · Security Desk

A China-linked threat actor tracked by Symantec as Longlegs, and by Microsoft as Storm-2603, has resumed attacks on critical-infrastructure and public-sector organizations using vulnerabilities in on-premises Microsoft SharePoint Server, according to threat intelligence published by Symantec's Threat Hunter Team on October 1 and corroborated by reporting in BleepingComputer and The Record.

The group is the operator behind Warlock ransomware. <cite index="28-3,28-4">Longlegs has exploited vulnerabilities in on-premises SharePoint Server to gain initial access to victim environments, targeting at least four organizations in Portuguese- and Spanish-speaking countries across Europe, Africa, and Latin America over the past two months.</cite> <cite index="29-6">The four confirmed victims include two critical infrastructure operators, a water utility and a telecommunications provider, a regional government body, and a university.</cite>

<cite index="28-6">Warlock emerged in June 2025 and gained attention weeks later when attackers were found exploiting zero-day vulnerabilities in Microsoft SharePoint Server, dubbed 'ToolShell,' tracked as CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771, according to the Symantec Threat Hunter Team's blog post.</cite> <cite index="29-9">Those flaws likely remain in the group's arsenal, alongside newer SharePoint flaws that CISA warned about in an advisory published in July 2026.</cite>

The kill chain is worth reading carefully. <cite index="34-1">Warlock's operators chain SharePoint vulnerability exploitation to webshell deployment, then use a bring-your-own-vulnerable-driver technique via K7RKScan.sys for security evasion, and finally distribute the ransomware binary through SYSVOL.</cite> <cite index="33-7">The target class is self-hosted SharePoint servers, not Microsoft 365 tenants</cite>, which is a meaningful distinction: organizations that migrated to cloud-hosted SharePoint aren't in this particular blast radius, but large portions of critical-infrastructure operators haven't made that move.

A few things need flagging before treating the Symantec report as a settled picture. The attribution to a "China-nexus" actor is a moderate-confidence assessment, not a confirmed government attribution. <cite index="29-4,29-5">Symantec identifies the group as Longlegs and has previously tied it to older activity clusters known as CL-CRI-1040, CamoFei, and ChamelGang,</cite> but clustering historical activity doesn't by itself confirm state direction. The ransomware-as-cover-for-espionage question, standard with China-nexus actors, is unresolved in the public reporting.

The timing also lands in a rough policy week for critical-infrastructure cyber defense. <cite index="22-2,22-3">A GAO report published September 28 is the third in a series examining industry perspectives on federal cybersecurity regulation harmonization.</cite> <cite index="19-4">In that report, industry participants called for establishing consistent definitions for incident-reporting timeframes and thresholds and designating a lead agency to coordinate and receive cyber incident reports.</cite> <cite index="20-1">GAO's July review identified 117 cybersecurity regulations established by 37 federal agencies for private entities across nine critical infrastructure sectors.</cite> <cite index="20-6">Of those, 80, roughly 70 percent, had the same kind of reporting requirement as at least one other regulation.</cite>

<cite index="19-6">GAO noted that conflicting guidance, inconsistencies, higher compliance costs, and redundant requirements can result when critical infrastructure sectors are subject to multiple cybersecurity regulations.</cite> That structural problem isn't hypothetical. A water utility navigating a Warlock intrusion right now faces a pile of potentially overlapping federal reporting clocks in addition to the operational response, and nobody has yet designated a single inbox.

<cite index="23-5,23-6">CISA is due to issue a final rule implementing the Cyber Incident Reporting for Critical Infrastructure Act of 2022; while that rule was expected in May 2026, it has been delayed until September 2026.</cite> There's no public confirmation it's been issued yet.

Organizations running on-premises SharePoint Server, particularly in water, energy, and telecoms, should treat the Symantec advisory as a primary source and cross-reference the CISA July advisory for the newer CVEs. The webshell-to-BYOVD-to-SYSVOL sequence Symantec documented gives defenders concrete detection points. Whether they have the logging turned on to catch it is a different question.

Sources cited:
- Symantec Threat Hunter Team (security.com) (https://www.security.com/threat-intelligence/warlock-ransomware-critical-infrastructure)
- Industrial Cyber, Symantec/Warlock report (https://industrialcyber.co/ransomware/symantec-reports-warlock-ransomware-group-targets-water-telecom-government-organizations-through-sharepoint-flaws/)
- Broadcom Security Center, Warlock bulletin (https://www.broadcom.com/support/security-center/protection-bulletin/warlock-ransomware-targets-water-and-telecom-operators)
- GAO-26-109197 (September 28, 2026) (https://www.gao.gov/products/gao-26-109197)
- GAO-26-108606 (July 22, 2026) (https://www.gao.gov/products/gao-26-108606)
- Industrial Cyber, GAO regulation overlap report (https://industrialcyber.co/regulation-standards-and-compliance/gao-finds-overlapping-federal-cyber-regulations-create-reporting-challenges-for-critical-infrastructure/)
- HIPAA Journal, CIRCIA and GAO duplicative requirements (https://www.hipaajournal.com/gao-potentially-duplicative-cyber-reporting-requirements-critical-infrastructure/)
- SecureInSeconds, Warlock/SharePoint SMB check (October 4, 2026) (https://www.secureinseconds.com/blog/2026-10-04-warlock-ransomware-sharepoint-smb)

Reporting by Renée Kovac, Correspondent, for the Security desk · ETL Newswire staff
Read more at the source

This release was originally distributed via ETL Newswire. Visit Symantec Threat Hunter Team (security.com) for the full story, related releases, and contact information.

Visit Symantec Threat Hunter Team (security.com) →