Warlock ransomware is still getting in through on-premises SharePoint, including water and telecom operators.
What happened
Symantec, writing as Broadcom, reported on 1 October that the China-nexus operator behind Warlock (tracked as Longlegs, also Storm-2603) hit at least four organizations in the past two months.
In one intrusion the group pushed an AV-killing tool to at least 40 hosts in about two hours, then deployed Warlock on at least 33 by staging it in SYSVOL so domain replication did the delivery. They also abused a signed K7RKScan driver and Visual Studio Code tunnels for covert access.
Who is affected
- A water utility, a telecommunications provider, a regional government body, and a university
- Victims were in Portuguese- and Spanish-speaking countries across Europe, Africa, and Latin America
- Initial access is still on-premises SharePoint, including the 2025 ToolShell chain and later SharePoint flaws
What to do now
- If any client still runs internet-facing SharePoint Server, confirm the July 2025 fixes and later SharePoint fixes.
- Look for unexpected webshells under LAYOUTS, and for new script drops in SYSVOL.
Unpatched on-prem SharePoint is an initial-access product, not a collaboration server.
Source: Symantec: Warlock hits water and telecom operators
Also on the blog
Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.