Home › Intelligence › Brief
BREACH BRIEF🟠 High Ransomware

Warlock Ransomware Strikes Water Utility and Telecom Operator via SharePoint Zero‑Days

Longlegs used SharePoint zero‑day exploits to infiltrate a water utility and a telecom provider, disabling security tools and deploying ransomware on dozens of hosts. The incident underscores the need for auditable incident‑response controls and continuous monitoring.

LiveThreat™ Intelligence · 📅 October 01, 2026· 📰 security.com
🟠
Severity
High
RW
Type
Ransomware
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
4 recommended
📰
Source
security.com

Warlock Ransomware Strikes Water Utility and Telecom Operator via SharePoint Zero‑Days

What Happened – The China‑nexus “Longlegs” group deployed Warlock ransomware against a water‑utility and a telecommunications provider in Portuguese‑ and Spanish‑speaking regions. Attackers leveraged a chain of Microsoft SharePoint Server zero‑day exploits (CVE‑2025‑49704, CVE‑2025‑49706, CVE‑2025‑53770, CVE‑2025‑53771) to gain initial access, disabled security software on ~40 hosts, and then propagated ransomware through the domain’s SYSVOL share to at least 33 machines.

Why It Matters for Trust & Control Assurance

  • Demonstrates the need for continuous monitoring of privileged share points and rapid detection of exploit activity – a core incident‑response control.
  • Highlights the importance of maintaining auditable evidence of ransomware containment and recovery steps to satisfy regulators and auditors.
  • Aligns with the Control Mapping capability, which helps organizations map incident‑response controls to multiple frameworks and produce defensible audit artifacts.

Who Is Affected – Critical‑infrastructure operators in the utilities and telecommunications sectors (energy/utilities, telecom).

Recommended Actions

  • Verify that all on‑premises SharePoint deployments are patched against the disclosed CVEs; apply mitigations where patches are unavailable.
  • Strengthen endpoint detection and response (EDR) to flag driver‑based security‑software disable attempts.
  • Update ransomware incident‑response playbooks to include SYSVOL‑based propagation detection and evidence‑collection steps.
  • Capture and retain logs from SharePoint, domain controllers, and endpoint agents as continuous control‑assurance evidence.

Technical Notes

  • Attack vector: Exploitation of SharePoint Server zero‑day vulnerabilities (ToolShell chain).
  • Tools used: Signed driver K7RKScan to disable AV, Visual Studio Code tunneling for covert access, webshells dropped in SharePoint LAYOUTS directory.
  • Impact: Ransomware deployed on 33+ hosts, security software disabled on ~40 hosts, likely service disruption for the affected utilities.

Source: Broadcom Symantec Blog – Warlock Ransomware Targets Critical Infrastructure

📰 Original Source
https://www.security.com/threat-intelligence/warlock-ransomware-critical-infrastructure ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Misconfigurations are control gaps in disguise.

Verisq AI Trust Operations turns findings like this into mapped controls with continuous evidence, keeping your audit readiness current instead of point-in-time.

Map your controls with Verisq AI Trust Operations →