INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Warlock ransomware breaches SharePoint at telecom operator's water facility
| 2026-10-02 18:33 CRITICAL HIGH RANSOMWARE & EXTORTION CRITICAL INFRASTRUCTURE & OT
Executive Summary
AI-generated
On October 2, 2026, the China-linked ransomware group Warlock targeted a water utility, a telecom provider, a regional government body, and a university in countries speaking Portuguese and Spanish across Europe, Africa, and Latin America. The attackers exploited SharePoint vulnerabilities to gain initial access, using exploits from ToolShell (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771) observed by Microsoft in August 2026. Warlock ransomware was attributed to the group Longlegs, also known as Storm-2603, with EDR killer deployed on at least 40 hosts. The attackers used a tool that disabled protection software within two hours of initial access and then launched Warlock ransomware on at least 33 hosts, dropping web shells designed for multiple SharePoint versions.
Technical Mitigations AI-generated
• Patch SharePoint vulnerabilities ToolShell (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771) to prevent exploitation.
• Block BYOVD technique using a signed K7RKScan driver vulnerable to CVE-2025-1055.
• Monitor for NetExec penetration testing framework usage on compromised systems.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CarbonCarbon
CVE-2025-49704CVE-2025-49704
CVE-2025-53771CVE-2025-53771
CVE-2025-1055CVE-2025-1055
CVE-2025-49706CVE-2025-49706
CVE-2025-53770CVE-2025-53770
Target & Sectors
LATAM
LATAM
AFRICA
AFRICA
EUROPE
EUROPE
energyenergy
telecommunicationstelecommunications
Incident Timeline
June 2025
The Warlock ransomware attackers exploited a chain of zero-day vulnerabilities in Microsoft SharePoint known as ToolShell to target at least 33 hosts.
Click on any entity below to view its context and source!
vulnerability
CVE-2025-49704
The gang emerged in June 2025 and gained notoriety a month later after exploiting a chain of zero-day vulnerabilities in Microsoft SharePoint known as
ToolShell
(CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771).
organisation
CVE-2025-49706
The gang emerged in June 2025 and gained notoriety a month later after exploiting a chain of zero-day vulnerabilities in Microsoft SharePoint known as
ToolShell
(CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771).
organisation
CVE-2025-53770
The gang emerged in June 2025 and gained notoriety a month later after exploiting a chain of zero-day vulnerabilities in Microsoft SharePoint known as
ToolShell
(CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771).
organisation
CVE-2025-53771
The gang emerged in June 2025 and gained notoriety a month later after exploiting a chain of zero-day vulnerabilities in Microsoft SharePoint known as
ToolShell
(CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771).
organisation
Microsoft SharePoint
The gang emerged in June 2025 and gained notoriety a month later after exploiting a chain of zero-day vulnerabilities in Microsoft SharePoint known as
ToolShell
(CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771).
organisation
Microsoft
By August, Microsoft observed state-backed hacking groups Linen Typhoon and Violet Typhoon using ToolShell exploits in attacks, along with a ransomware threat actor the company tracks as Storm-2603.
organisation
Violet Typhoon
By August, Microsoft observed state-backed hacking groups Linen Typhoon and Violet Typhoon using ToolShell exploits in attacks, along with a ransomware threat actor the company tracks as Storm-2603.
organisation
Storm-2603
By August, Microsoft observed state-backed hacking groups Linen Typhoon and Violet Typhoon using ToolShell exploits in attacks, along with a ransomware threat actor the company tracks as Storm-2603.
organisation
EDR
EDR killer deployed to 40 hosts
Cybersecurity company Symantec identifies the same actor as Longlegs and attributes the development of the Warlock ransomware to the group.
organisation
Cybersecurity company Symantec
EDR killer deployed to 40 hosts
Cybersecurity company Symantec identifies the same actor as Longlegs and attributes the development of the Warlock ransomware to the group.
infrastructure
40 hosts
EDR killer deployed to 40 hosts
Cybersecurity company Symantec identifies the same actor as Longlegs and attributes the development of the Warlock ransomware to the group.
infrastructure
33 hosts
The attacker then launched Warlock ransomware on at least 33 hosts.
infrastructure
Vs Code
Using VS Code's tunneling capability
The ransomware payload was staged in the domain’s SYSVOL share, a location that stores public files and is replicated across every domain controller.
During the attack, the main executable file for Visual Studio Code Insiders was installed as a service to enable connecting remotely to compromised machines using VS Code's built-in tunneling capability.
infrastructure
Visual Studio Code
During the attack, the main executable file for Visual Studio Code Insiders was installed as a service to enable connecting remotely to compromised machines using VS Code's built-in tunneling capability.
organisation
CVE-2025-1055
Symantec and Carbon Black researchers say that in some attacks attributed to Longlegs, an AV/EDR-killing tool was deployed via the bring your own vulnerable driver (BYOVD) technique using a signed K7RKScan driver vulnerable to CVE-2025-1055.
organisation
Group Policy
This is “a known method of pushing a payload out for execution by a logon script or Group Policy object across an entire network at once, rather than one host at a time,” the
researchers say
.
organisation
NetExec
On one of the systems, the researchers found the open-source penetration testing framework NetExec, which helped the attacker with Active Directory enumeration, credential spraying, and remote command execution.
organisation
Active Directory
On one of the systems, the researchers found the open-source penetration testing framework NetExec, which helped the attacker with Active Directory enumeration, credential spraying, and remote command execution.
organisation
NFL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
organisation
CHANEL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
July 22
Threat actors deployed a tool that disabled protection software on at least 40 hosts within about two hours of gaining initial access.
Click on any entity below to view its context and source!
tactic
Reconnaissance
Analysis of the intrusion on July 22 revealed that two days after gaining initial access, the threat actor engaged in reconnaissance activity and deleted what seemed like staging artifacts.
infrastructure
40 hosts
According to the researchers, in one intrusion that started on July 22, the threat actor deployed a tool that disabled protection software on “at least 40 hosts within about two hours.”
July 31st
Warlock ransomware appeared almost as soon as protection was disabled on each host, following the deployment of an AV/EDR killer.
Click on any entity below to view its context and source!
tactic
Ransomware
The final stage of the attack occurred on July 31st, after deploying the AV/EDR killer, with Warlock ransomware “appearing almost as soon as protection was disabled on each host.”
organisation
AV
The final stage of the attack occurred on July 31st, after deploying the AV/EDR killer, with Warlock ransomware “appearing almost as soon as protection was disabled on each host.”
2026/10/02
The China-linked Warlock ransomware group exploited SharePoint vulnerabilities to gain initial access and targeted multiple entities, including a water utility, telecom provider, regional government body, and university.
Click on any entity below to view its context and source!
organisation
SharePoint
Warlock ransomware breach SharePoint in water, telecom operator attacks.
Tactical Metrics
Metrics
infrastructure
40
Hosts
Click for context!
EDR killer deployed to 40 hosts
Cybersecurity company Symantec identifies the same actor as Longlegs and attributes the development of the Warlock ransomware to the group.
According to the researchers, in one intrusion that started on July 22, the threat actor deployed a tool that disabled protection software on “at least 40 hosts within about two hours.”
Metrics
infrastructure
33
Hosts
The attacker then launched Warlock ransomware on at least 33 hosts.
Metrics
infrastructure
Vs Code
Affected Product
Using VS Code's tunneling capability
The ransomware payload was staged in the domain’s SYSVOL share, a location that stores public files and is replicated across every domain controller.
During the attack, the main executable file for Visual Studio Code Insiders was installed as a service to enable connecting remotely to compromised machines using VS Code's built-in tunneling capability.
Metrics
infrastructure
Visual Studio Code
Affected Product
During the attack, the main executable file for Visual Studio Code Insiders was installed as a service to enable connecting remotely to compromised machines using VS Code's built-in tunneling capability.
Intelligence Sources
BleepingComputer
2026-10-02
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-06T11:04
Comprehensive Tactical Telemetry
Highly Correlated Entities
17x
organisation
Identified Entity
SharePoint
entity
5x
vulnerability
Exploited CVE
CVE-2025-49704
cve
3x
timeline
Temporal Reference
July 22
date
3x
target region
Target Region
AFRICA
region
2x
tactic
Cyber Operation Type
Ransomware
tactic
2x
infrastructure
Hosts
40
hosts
2x
infrastructure
Affected Product
Vs Code
software
2x
target region
Target Country
Portugal
country
Contextual Telemetry
Context Block
4 METRICS
source region
Origin Country
China
country
industry
Targeted Sector
Government
sector
attribution
Attributing Entity
Warlock
authority
malware
Malware Payload
Carbon
tool
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.