INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Warlock ransomware breaches SharePoint at telecom operator's water facility

| 2026-10-02 18:33 CRITICAL HIGH RANSOMWARE & EXTORTION CRITICAL INFRASTRUCTURE & OT
Executive Summary
AI-generated
On October 2, 2026, the China-linked ransomware group Warlock targeted a water utility, a telecom provider, a regional government body, and a university in countries speaking Portuguese and Spanish across Europe, Africa, and Latin America. The attackers exploited SharePoint vulnerabilities to gain initial access, using exploits from ToolShell (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771) observed by Microsoft in August 2026. Warlock ransomware was attributed to the group Longlegs, also known as Storm-2603, with EDR killer deployed on at least 40 hosts. The attackers used a tool that disabled protection software within two hours of initial access and then launched Warlock ransomware on at least 33 hosts, dropping web shells designed for multiple SharePoint versions.
Technical Mitigations AI-generated
• Patch SharePoint vulnerabilities ToolShell (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771) to prevent exploitation. • Block BYOVD technique using a signed K7RKScan driver vulnerable to CVE-2025-1055. • Monitor for NetExec penetration testing framework usage on compromised systems.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CarbonCarbon CVE-2025-49704CVE-2025-49704 CVE-2025-53771CVE-2025-53771 CVE-2025-1055CVE-2025-1055 CVE-2025-49706CVE-2025-49706 CVE-2025-53770CVE-2025-53770
Target & Sectors
LATAM LATAM AFRICA AFRICA EUROPE EUROPE energyenergy telecommunicationstelecommunications
Incident Timeline
‎June 2025
The Warlock ransomware attackers exploited a chain of zero-day vulnerabilities in Microsoft SharePoint known as ToolShell to target at least 33 hosts.
vulnerability CVE-2025-49704
organisation CVE-2025-49706
organisation CVE-2025-53770
organisation CVE-2025-53771
organisation Microsoft SharePoint
organisation Microsoft
organisation Violet Typhoon
organisation Storm-2603
organisation EDR
organisation Cybersecurity company Symantec
infrastructure 40 hosts
infrastructure 33 hosts
infrastructure Vs Code
infrastructure Visual Studio Code
organisation CVE-2025-1055
organisation Group Policy
organisation NetExec
organisation Active Directory
organisation NFL
organisation CHANEL
‎July 22
Threat actors deployed a tool that disabled protection software on at least 40 hosts within about two hours of gaining initial access.
tactic Reconnaissance
infrastructure 40 hosts
‎July 31st
Warlock ransomware appeared almost as soon as protection was disabled on each host, following the deployment of an AV/EDR killer.
tactic Ransomware
organisation AV
‎2026/10/02
The China-linked Warlock ransomware group exploited SharePoint vulnerabilities to gain initial access and targeted multiple entities, including a water utility, telecom provider, regional government body, and university.
organisation SharePoint
Tactical Metrics
Metrics
infrastructure
40
Hosts
Metrics
infrastructure
33
Hosts
Metrics
infrastructure
‎Vs Code
Affected Product
Metrics
infrastructure
‎Visual Studio Code
Affected Product
Intelligence Sources