Fresh Timeline Details Surface on Warlock's Critical-Infrastructure Hits
BleepingComputer, drawing on research from Symantec, published additional forensic detail on October 2, 2026 about a China-linked ransomware campaign already known to have breached a water utility, a telecommunications provider, a regional government body, and a university by exploiting on-premises Microsoft SharePoint Server flaws. The ransomware, tracked as Warlock, is operated by a threat actor Symantec calls Longlegs — also known as Storm-2603 (Microsoft), CL-CRI-1040 (Palo Alto Unit 42), and CamoFei/ChamelGang (TeamT5/SentinelOne). CosmicBytez Labs first covered this campaign on October 1; this report adds a documented, day-by-day intrusion timeline for one of the attacks, the full list of exploited ToolShell CVEs, and context on a newer round of SharePoint flaws that CISA flagged in July 2026 — details that sharpen the scope of an already-serious critical-infrastructure exposure. Victim organizations have not been named publicly; researchers have disclosed only sectors and a regional concentration in Portuguese- and Spanish-speaking countries across Europe, Africa, and Latin America.
Incident Details
| Attribute | Value |
|---|---|
| Threat actor | Longlegs (Symantec) — aka Storm-2603 (Microsoft), CL-CRI-1040 (Unit 42), CamoFei/ChamelGang (TeamT5/SentinelOne) |
| Ransomware family | Warlock |
| Origin | China-nexus |
| Initial access | Webshell planted in SharePoint's LAYOUTS directory via ToolShell exploitation |
| ToolShell CVEs | CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, CVE-2025-53771 |
| BYOVD driver abused | K7RKScan (CVE-2025-1055) |
| Documented intrusion window | July 22 – July 31, 2026 (one disclosed case) |
| AV/EDR killer reach | 40+ hosts disabled within roughly two hours |
| Ransomware deployment reach | At least 33 hosts |
| Recon / credential tooling | NetExec |
| Covert access | Visual Studio Code remote tunneling; DLL sideloading |
| Victim sectors | Water utility, telecommunications provider, regional government body, university |
| Victim geography | Portuguese- and Spanish-speaking countries across Europe, Africa, and Latin America |
| Named victims | Not publicly disclosed — Symantec and BleepingComputer report sectors only |
| Newer SharePoint CVEs in play (CISA, July 2026) | CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, CVE-2026-58644, CVE-2026-50522, CVE-2026-55040 |
How the Attack Chain Unfolded
A Documented Nine-Day Intrusion
For at least one of the four confirmed victims, researchers were able to reconstruct a detailed timeline. The intrusion began on July 22 with the deployment of an ASPX webshell inside the SharePoint LAYOUTS directory, exploiting the ToolShell vulnerability chain. Attackers then spent July 24 conducting internal reconnaissance before confirming remote code execution on July 27. Privilege escalation to administrative-level access followed on July 28. The operation culminated on July 31, when the group pushed an AV/EDR-killer utility to more than 40 hosts within roughly two hours, immediately followed by Warlock ransomware deployment across at least 33 hosts. The nine-day gap between initial webshell access and final encryption suggests a deliberate staging period rather than a smash-and-grab operation.
Exploiting the Full ToolShell Chain
The SharePoint entry point traces back to ToolShell, the exploit chain first disclosed as a zero-day on July 19, 2025, comprising four chained flaws: CVE-2025-49704 (RCE), CVE-2025-49706 (spoofing/auth bypass), and the headline pair CVE-2025-53770 and CVE-2025-53771 (unauthenticated RCE via unsafe deserialization). Once inside, the webshell extracts the server's ASP.NET machine keys, which the attackers use to forge signed __VIEWSTATE payloads — granting arbitrary code execution inside the SharePoint application pool without valid credentials.
Recon, Credential Spraying, and Living-off-the-Land Access
Beyond the webshell, researchers observed the group using NetExec, an open-source post-exploitation tool, for internal network reconnaissance and credential-spraying against discovered accounts. For covert, low-noise remote access that blends with legitimate developer traffic, the operators again abused Visual Studio Code's remote tunneling feature, and separately used DLL sideloading to load malicious code through a trusted executable — two techniques designed to minimize detections from security tooling still running at that point in the intrusion.
Kernel-Level Evasion Before Encryption
Before deploying ransomware, the group pushed a security-tooling-termination utility that abuses the signed but vulnerable K7RKScan driver (CVE-2025-1055) in a bring-your-own-vulnerable-driver (BYOVD) technique, killing AV and EDR processes from kernel space where user-mode protections cannot intervene. This step reached more than 40 hosts in the documented case before Warlock itself was pushed to roughly 33 of them.
A Widening SharePoint Exposure
The campaign's persistence is compounded by a separate, larger problem: on-premises SharePoint Server has had a rough 2026. In July 2026, CISA warned of active exploitation of six additional SharePoint vulnerabilities — CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, CVE-2026-58644, CVE-2026-50522, and CVE-2026-55040 — on top of the 2025 ToolShell flaws. Shadowserver scans around that advisory found nearly 10,000 internet-exposed SharePoint servers, with more than 800 still unpatched against just two of the six CVEs. Researchers note Warlock's operators have continued exploiting SharePoint bugs more than a year after ToolShell's debut, a pattern consistent with a 2025 SharePoint hacking spree that is estimated to have hit roughly 400 governments and businesses worldwide, including the U.S. National Nuclear Security Administration, the National Institutes of Health, the Department of Homeland Security, and Swiss government institutions breached that August.
Impact Assessment
| Impact Area | Description |
|---|---|
| Water sector | A compromised water utility raises operational-technology and public-safety concerns if IT/OT segmentation is weak |
| Telecommunications | A breached telecom operator risks service disruption and potential exposure of subscriber or network metadata |
| Government operations | The regional government body's breach risks citizen data exposure and disrupted public services |
| Education sector | University compromise risks research data, intellectual property, and student/staff PII |
| Broader SharePoint exposure | Nearly 10,000 internet-facing SharePoint servers remain discoverable, with hundreds still unpatched against actively exploited 2026 CVEs |
| Attribution complexity | A China-nexus actor running an indiscriminate ransomware operation blurs the line between cybercrime and state-associated tradecraft |
Recommendations
For SharePoint and Infrastructure Administrators
- Patch all ten relevant CVEs: the four 2025 ToolShell flaws (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, CVE-2025-53771) and the six 2026 flaws CISA flagged (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, CVE-2026-58644, CVE-2026-50522, CVE-2026-55040)
- Rotate ASP.NET machine keys on every on-premises SharePoint farm that has not rotated since the ToolShell disclosure
- Audit the
LAYOUTSdirectory and other web-accessible SharePoint paths for unauthorized.aspxwebshells - Inventory internet-facing SharePoint instances against Shadowserver-style exposure data; prioritize any server still unpatched against the six newer 2026 CVEs
For Security Operations Teams
- Hunt for NetExec activity, anomalous credential-spraying patterns, and unexpected DLL sideloading from trusted executables
- Alert on mass AV/EDR process termination across dozens of hosts within a short window — a near-certain pre-encryption signal
- Flag outbound traffic consistent with VS Code remote tunneling from servers with no legitimate development function
- Hunt specifically for the K7RKScan driver (CVE-2025-1055) and other known-vulnerable signed drivers loaded outside expected contexts
- Maintain offline, immutable backups, particularly for domain controllers and systems supporting operational technology
For Water, Telecom, Government, and Education-Sector Leadership
- Treat on-premises SharePoint as an active, currently exploited exposure rather than a theoretical risk, given the documented nine-day path from webshell to ransomware
- Segment OT/ICS networks from corporate IT, especially at water utilities and telecom operators where service continuity has public-safety implications
- Engage regional ISACs/CSIRTs, particularly in Portuguese- and Spanish-speaking markets where this group has concentrated recent activity
Key Takeaways
- Warlock ransomware, operated by the China-nexus actor Longlegs/Storm-2603, breached a water utility, telecom operator, regional government body, and university via on-premises SharePoint flaws; none of the victims has been named publicly.
- New reporting reconstructs a documented nine-day intrusion timeline (July 22 – July 31, 2026) from initial webshell to full ransomware deployment across 33+ hosts.
- Initial access exploited the complete four-CVE ToolShell chain (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, CVE-2025-53771), with NetExec, DLL sideloading, and VS Code tunneling supporting reconnaissance and covert access.
- A BYOVD technique abusing the signed K7RKScan driver (CVE-2025-1055) disabled security tooling on 40+ hosts in roughly two hours before encryption began.
- CISA's July 2026 advisory on six additional actively exploited SharePoint CVEs — layered on top of 2025's ToolShell flaws — means nearly 10,000 internet-exposed SharePoint servers remain a live attack surface, with hundreds still unpatched.
- This is the same broader campaign CosmicBytez Labs covered on October 1; organizations in the water, telecom, government, and education sectors — especially in Iberia and Latin America — should treat unpatched on-premises SharePoint as an urgent remediation priority.
Sources
- Warlock ransomware breach SharePoint in water, telecom operator attacks — BleepingComputer
- Warlock Ransomware Attackers Hit Water and Telecom Operators — Symantec/Security.com
- 'Warlock' ransomware used in attacks on critical infrastructure in Portuguese, Spanish-speaking countries — The Record
- CISA Urges SharePoint Hardening After New Exploitations — CISA
Related reading: Warlock Ransomware Hits Large Spanish, Portuguese Orgs — CosmicBytez Labs' initial coverage of this campaign, published October 1, 2026.