NEWS

Warlock Ransomware Breaches Water Utility, Telecom via SharePoint Flaws

New forensic detail reveals a 9-day Warlock ransomware intrusion chain that hit a water utility, telecom operator, government body, and university.

Dylan H.

News Desk

October 2, 2026
8 min read
Warlock Ransomware Breaches Water Utility, Telecom via SharePoint Flaws

Fresh Timeline Details Surface on Warlock's Critical-Infrastructure Hits

BleepingComputer, drawing on research from Symantec, published additional forensic detail on October 2, 2026 about a China-linked ransomware campaign already known to have breached a water utility, a telecommunications provider, a regional government body, and a university by exploiting on-premises Microsoft SharePoint Server flaws. The ransomware, tracked as Warlock, is operated by a threat actor Symantec calls Longlegs — also known as Storm-2603 (Microsoft), CL-CRI-1040 (Palo Alto Unit 42), and CamoFei/ChamelGang (TeamT5/SentinelOne). CosmicBytez Labs first covered this campaign on October 1; this report adds a documented, day-by-day intrusion timeline for one of the attacks, the full list of exploited ToolShell CVEs, and context on a newer round of SharePoint flaws that CISA flagged in July 2026 — details that sharpen the scope of an already-serious critical-infrastructure exposure. Victim organizations have not been named publicly; researchers have disclosed only sectors and a regional concentration in Portuguese- and Spanish-speaking countries across Europe, Africa, and Latin America.


Incident Details

AttributeValue
Threat actorLonglegs (Symantec) — aka Storm-2603 (Microsoft), CL-CRI-1040 (Unit 42), CamoFei/ChamelGang (TeamT5/SentinelOne)
Ransomware familyWarlock
OriginChina-nexus
Initial accessWebshell planted in SharePoint's LAYOUTS directory via ToolShell exploitation
ToolShell CVEsCVE-2025-49704, CVE-2025-49706, CVE-2025-53770, CVE-2025-53771
BYOVD driver abusedK7RKScan (CVE-2025-1055)
Documented intrusion windowJuly 22 – July 31, 2026 (one disclosed case)
AV/EDR killer reach40+ hosts disabled within roughly two hours
Ransomware deployment reachAt least 33 hosts
Recon / credential toolingNetExec
Covert accessVisual Studio Code remote tunneling; DLL sideloading
Victim sectorsWater utility, telecommunications provider, regional government body, university
Victim geographyPortuguese- and Spanish-speaking countries across Europe, Africa, and Latin America
Named victimsNot publicly disclosed — Symantec and BleepingComputer report sectors only
Newer SharePoint CVEs in play (CISA, July 2026)CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, CVE-2026-58644, CVE-2026-50522, CVE-2026-55040

How the Attack Chain Unfolded

A Documented Nine-Day Intrusion

For at least one of the four confirmed victims, researchers were able to reconstruct a detailed timeline. The intrusion began on July 22 with the deployment of an ASPX webshell inside the SharePoint LAYOUTS directory, exploiting the ToolShell vulnerability chain. Attackers then spent July 24 conducting internal reconnaissance before confirming remote code execution on July 27. Privilege escalation to administrative-level access followed on July 28. The operation culminated on July 31, when the group pushed an AV/EDR-killer utility to more than 40 hosts within roughly two hours, immediately followed by Warlock ransomware deployment across at least 33 hosts. The nine-day gap between initial webshell access and final encryption suggests a deliberate staging period rather than a smash-and-grab operation.

Exploiting the Full ToolShell Chain

The SharePoint entry point traces back to ToolShell, the exploit chain first disclosed as a zero-day on July 19, 2025, comprising four chained flaws: CVE-2025-49704 (RCE), CVE-2025-49706 (spoofing/auth bypass), and the headline pair CVE-2025-53770 and CVE-2025-53771 (unauthenticated RCE via unsafe deserialization). Once inside, the webshell extracts the server's ASP.NET machine keys, which the attackers use to forge signed __VIEWSTATE payloads — granting arbitrary code execution inside the SharePoint application pool without valid credentials.

Recon, Credential Spraying, and Living-off-the-Land Access

Beyond the webshell, researchers observed the group using NetExec, an open-source post-exploitation tool, for internal network reconnaissance and credential-spraying against discovered accounts. For covert, low-noise remote access that blends with legitimate developer traffic, the operators again abused Visual Studio Code's remote tunneling feature, and separately used DLL sideloading to load malicious code through a trusted executable — two techniques designed to minimize detections from security tooling still running at that point in the intrusion.

Kernel-Level Evasion Before Encryption

Before deploying ransomware, the group pushed a security-tooling-termination utility that abuses the signed but vulnerable K7RKScan driver (CVE-2025-1055) in a bring-your-own-vulnerable-driver (BYOVD) technique, killing AV and EDR processes from kernel space where user-mode protections cannot intervene. This step reached more than 40 hosts in the documented case before Warlock itself was pushed to roughly 33 of them.

A Widening SharePoint Exposure

The campaign's persistence is compounded by a separate, larger problem: on-premises SharePoint Server has had a rough 2026. In July 2026, CISA warned of active exploitation of six additional SharePoint vulnerabilities — CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, CVE-2026-58644, CVE-2026-50522, and CVE-2026-55040 — on top of the 2025 ToolShell flaws. Shadowserver scans around that advisory found nearly 10,000 internet-exposed SharePoint servers, with more than 800 still unpatched against just two of the six CVEs. Researchers note Warlock's operators have continued exploiting SharePoint bugs more than a year after ToolShell's debut, a pattern consistent with a 2025 SharePoint hacking spree that is estimated to have hit roughly 400 governments and businesses worldwide, including the U.S. National Nuclear Security Administration, the National Institutes of Health, the Department of Homeland Security, and Swiss government institutions breached that August.

Impact Assessment

Impact AreaDescription
Water sectorA compromised water utility raises operational-technology and public-safety concerns if IT/OT segmentation is weak
TelecommunicationsA breached telecom operator risks service disruption and potential exposure of subscriber or network metadata
Government operationsThe regional government body's breach risks citizen data exposure and disrupted public services
Education sectorUniversity compromise risks research data, intellectual property, and student/staff PII
Broader SharePoint exposureNearly 10,000 internet-facing SharePoint servers remain discoverable, with hundreds still unpatched against actively exploited 2026 CVEs
Attribution complexityA China-nexus actor running an indiscriminate ransomware operation blurs the line between cybercrime and state-associated tradecraft

Recommendations

For SharePoint and Infrastructure Administrators

  • Patch all ten relevant CVEs: the four 2025 ToolShell flaws (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, CVE-2025-53771) and the six 2026 flaws CISA flagged (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, CVE-2026-58644, CVE-2026-50522, CVE-2026-55040)
  • Rotate ASP.NET machine keys on every on-premises SharePoint farm that has not rotated since the ToolShell disclosure
  • Audit the LAYOUTS directory and other web-accessible SharePoint paths for unauthorized .aspx webshells
  • Inventory internet-facing SharePoint instances against Shadowserver-style exposure data; prioritize any server still unpatched against the six newer 2026 CVEs

For Security Operations Teams

  • Hunt for NetExec activity, anomalous credential-spraying patterns, and unexpected DLL sideloading from trusted executables
  • Alert on mass AV/EDR process termination across dozens of hosts within a short window — a near-certain pre-encryption signal
  • Flag outbound traffic consistent with VS Code remote tunneling from servers with no legitimate development function
  • Hunt specifically for the K7RKScan driver (CVE-2025-1055) and other known-vulnerable signed drivers loaded outside expected contexts
  • Maintain offline, immutable backups, particularly for domain controllers and systems supporting operational technology

For Water, Telecom, Government, and Education-Sector Leadership

  • Treat on-premises SharePoint as an active, currently exploited exposure rather than a theoretical risk, given the documented nine-day path from webshell to ransomware
  • Segment OT/ICS networks from corporate IT, especially at water utilities and telecom operators where service continuity has public-safety implications
  • Engage regional ISACs/CSIRTs, particularly in Portuguese- and Spanish-speaking markets where this group has concentrated recent activity

Key Takeaways

  1. Warlock ransomware, operated by the China-nexus actor Longlegs/Storm-2603, breached a water utility, telecom operator, regional government body, and university via on-premises SharePoint flaws; none of the victims has been named publicly.
  2. New reporting reconstructs a documented nine-day intrusion timeline (July 22 – July 31, 2026) from initial webshell to full ransomware deployment across 33+ hosts.
  3. Initial access exploited the complete four-CVE ToolShell chain (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, CVE-2025-53771), with NetExec, DLL sideloading, and VS Code tunneling supporting reconnaissance and covert access.
  4. A BYOVD technique abusing the signed K7RKScan driver (CVE-2025-1055) disabled security tooling on 40+ hosts in roughly two hours before encryption began.
  5. CISA's July 2026 advisory on six additional actively exploited SharePoint CVEs — layered on top of 2025's ToolShell flaws — means nearly 10,000 internet-exposed SharePoint servers remain a live attack surface, with hundreds still unpatched.
  6. This is the same broader campaign CosmicBytez Labs covered on October 1; organizations in the water, telecom, government, and education sectors — especially in Iberia and Latin America — should treat unpatched on-premises SharePoint as an urgent remediation priority.

Sources

Related reading: Warlock Ransomware Hits Large Spanish, Portuguese Orgs — CosmicBytez Labs' initial coverage of this campaign, published October 1, 2026.