Warlock is still entering through on-prem SharePoint, including water and telecom
Still using on-prem SharePoint

Warlock is still entering through on-prem SharePoint, including water and telecom

Warlock ransomware is still getting in through on-premises SharePoint, including water and telecom operators.

What happened

Symantec, writing as Broadcom, reported on 1 October that the China-nexus operator behind Warlock (tracked as Longlegs, also Storm-2603) hit at least four organizations in the past two months.

In one intrusion the group pushed an AV-killing tool to at least 40 hosts in about two hours, then deployed Warlock on at least 33 by staging it in SYSVOL so domain replication did the delivery. They also abused a signed K7RKScan driver and Visual Studio Code tunnels for covert access.

Who is affected

  • A water utility, a telecommunications provider, a regional government body, and a university
  • Victims were in Portuguese- and Spanish-speaking countries across Europe, Africa, and Latin America
  • Initial access is still on-premises SharePoint, including the 2025 ToolShell chain and later SharePoint flaws

What to do now

  • If any client still runs internet-facing SharePoint Server, confirm the July 2025 fixes and later SharePoint fixes.
  • Look for unexpected webshells under LAYOUTS, and for new script drops in SYSVOL.

Unpatched on-prem SharePoint is an initial-access product, not a collaboration server.

Source: Symantec: Warlock hits water and telecom operators

Also on the blog

Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.

CISA lists two Zammad bugs that an AI-driven attack already chained to root
CVE-2026-102489 and CVE-2026-102490