China-Nexus Warlock Ransomware Hits Water Utility and Telecom via SharePoint Flaws
Symantec's Threat Hunter Team links the Longlegs group to fresh critical-infrastructure intrusions across Europe, Africa, and Latin America, all riding the same on-premises SharePoint exploit chain flagged by CISA in July.
A China-linked threat actor tracked by Symantec as Longlegs, and by Microsoft as Storm-2603, has resumed attacks on critical-infrastructure and public-sector organizations using vulnerabilities in on-premises Microsoft SharePoint Server, according to threat intelligence published by Symantec's Threat Hunter Team on October 1 and corroborated by reporting in BleepingComputer and The Record.
The group is the operator behind Warlock ransomware. <cite index="28-3,28-4">Longlegs has exploited vulnerabilities in on-premises SharePoint Server to gain initial access to victim environments, targeting at least four organizations in Portuguese- and Spanish-speaking countries across Europe, Africa, and Latin America over the past two months.</cite> <cite index="29-6">The four confirmed victims include two critical infrastructure operators, a water utility and a telecommunications provider, a regional government body, and a university.</cite>
<cite index="28-6">Warlock emerged in June 2025 and gained attention weeks later when attackers were found exploiting zero-day vulnerabilities in Microsoft SharePoint Server, dubbed 'ToolShell,' tracked as CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771, according to the Symantec Threat Hunter Team's blog post.</cite> <cite index="29-9">Those flaws likely remain in the group's arsenal, alongside newer SharePoint flaws that CISA warned about in an advisory published in July 2026.</cite>
The kill chain is worth reading carefully. <cite index="34-1">Warlock's operators chain SharePoint vulnerability exploitation to webshell deployment, then use a bring-your-own-vulnerable-driver technique via K7RKScan.sys for security evasion, and finally distribute the ransomware binary through SYSVOL.</cite> <cite index="33-7">The target class is self-hosted SharePoint servers, not Microsoft 365 tenants</cite>, which is a meaningful distinction: organizations that migrated to cloud-hosted SharePoint aren't in this particular blast radius, but large portions of critical-infrastructure operators haven't made that move.
A few things need flagging before treating the Symantec report as a settled picture. The attribution to a "China-nexus" actor is a moderate-confidence assessment, not a confirmed government attribution. <cite index="29-4,29-5">Symantec identifies the group as Longlegs and has previously tied it to older activity clusters known as CL-CRI-1040, CamoFei, and ChamelGang,</cite> but clustering historical activity doesn't by itself confirm state direction. The ransomware-as-cover-for-espionage question, standard with China-nexus actors, is unresolved in the public reporting.
The timing also lands in a rough policy week for critical-infrastructure cyber defense. <cite index="22-2,22-3">A GAO report published September 28 is the third in a series examining industry perspectives on federal cybersecurity regulation harmonization.</cite> <cite index="19-4">In that report, industry participants called for establishing consistent definitions for incident-reporting timeframes and thresholds and designating a lead agency to coordinate and receive cyber incident reports.</cite> <cite index="20-1">GAO's July review identified 117 cybersecurity regulations established by 37 federal agencies for private entities across nine critical infrastructure sectors.</cite> <cite index="20-6">Of those, 80, roughly 70 percent, had the same kind of reporting requirement as at least one other regulation.</cite>
<cite index="19-6">GAO noted that conflicting guidance, inconsistencies, higher compliance costs, and redundant requirements can result when critical infrastructure sectors are subject to multiple cybersecurity regulations.</cite> That structural problem isn't hypothetical. A water utility navigating a Warlock intrusion right now faces a pile of potentially overlapping federal reporting clocks in addition to the operational response, and nobody has yet designated a single inbox.
<cite index="23-5,23-6">CISA is due to issue a final rule implementing the Cyber Incident Reporting for Critical Infrastructure Act of 2022; while that rule was expected in May 2026, it has been delayed until September 2026.</cite> There's no public confirmation it's been issued yet.
Organizations running on-premises SharePoint Server, particularly in water, energy, and telecoms, should treat the Symantec advisory as a primary source and cross-reference the CISA July advisory for the newer CVEs. The webshell-to-BYOVD-to-SYSVOL sequence Symantec documented gives defenders concrete detection points. Whether they have the logging turned on to catch it is a different question.
Sources cited:
- Symantec Threat Hunter Team (security.com) (https://www.security.com/threat-intelligence/warlock-ransomware-critical-infrastructure)
- Industrial Cyber, Symantec/Warlock report (https://industrialcyber.co/ransomware/symantec-reports-warlock-ransomware-group-targets-water-telecom-government-organizations-through-sharepoint-flaws/)
- Broadcom Security Center, Warlock bulletin (https://www.broadcom.com/support/security-center/protection-bulletin/warlock-ransomware-targets-water-and-telecom-operators)
- GAO-26-109197 (September 28, 2026) (https://www.gao.gov/products/gao-26-109197)
- GAO-26-108606 (July 22, 2026) (https://www.gao.gov/products/gao-26-108606)
- Industrial Cyber, GAO regulation overlap report (https://industrialcyber.co/regulation-standards-and-compliance/gao-finds-overlapping-federal-cyber-regulations-create-reporting-challenges-for-critical-infrastructure/)
- HIPAA Journal, CIRCIA and GAO duplicative requirements (https://www.hipaajournal.com/gao-potentially-duplicative-cyber-reporting-requirements-critical-infrastructure/)
- SecureInSeconds, Warlock/SharePoint SMB check (October 4, 2026) (https://www.secureinseconds.com/blog/2026-10-04-warlock-ransomware-sharepoint-smb)
This release was originally distributed via ETL Newswire. Visit Symantec Threat Hunter Team (security.com) for the full story, related releases, and contact information.
Visit Symantec Threat Hunter Team (security.com) →