WARLOCK RANSOMWARE HITS WATER AND TELECOM OPERATORS THROUGH SHAREPOINT FLAWS

NEW ATTACKS TARGET CRITICAL INFRASTRUCTURE

October 2, 2026 — The operators of Warlock ransomware have compromised at least four organizations during a two-month campaign targeting Portuguese- and Spanish-speaking countries, according to new research from Symantec’s Threat Hunter Team.

The identified victims include a water utility, telecommunications provider, regional government body and university across Europe, Africa and Latin America. Attackers continued exploiting vulnerabilities in on-premises Microsoft SharePoint Server to enter networks.

This represents a material update to earlier Warlock activity because the campaign has expanded into essential water and telecommunications services and includes a documented method for rapidly disabling defenses and distributing ransomware across Windows domains.

ATTACKERS DISABLED SECURITY ON AT LEAST 40 SYSTEMS

In one critical-infrastructure intrusion, Symantec observed the attackers deploy an antivirus and endpoint-detection killer to at least 40 hosts within roughly two hours.

Warlock ransomware appeared on at least 33 systems soon after those protections were disabled. The attackers placed the ransomware inside the victim’s Active Directory SYSVOL share, allowing ordinary domain replication to distribute it between domain controllers and other systems.

This technique effectively turns trusted Windows infrastructure into a ransomware-delivery mechanism. It can also make containment more difficult because removing the payload from one endpoint does not eliminate copies replicated elsewhere.

SHAREPOINT REMAINS THE INITIAL ENTRY POINT

Symantec assesses that the group typically compromises internet-accessible, on-premises SharePoint servers before dropping web shells into directories used by multiple SharePoint versions.

The web shells harvest ASP.NET machine keys, which can be used to create validly signed payloads and execute code within the SharePoint application pool.

Warlock previously exploited the ToolShell vulnerability chain involving:

  • CVE-2025-49704
  • CVE-2025-49706
  • CVE-2025-53770
  • CVE-2025-53771

Symantec said those vulnerabilities likely remain available to the attackers alongside newer SharePoint flaws highlighted in a 2026 CISA warning. However, the researchers did not conclusively identify the precise vulnerability used in every recent intrusion.

The attacks affect on-premises SharePoint deployments. SharePoint Online in Microsoft 365 is not vulnerable to the original ToolShell flaws.

Leave a Comment

Your email address will not be published. Required fields are marked *