Monday 5 October 2026 538 stories on file Full archive
Daily Edition
newscms

Volume III Edition Daily

Warlock Ransomware Hits a Water Utility and a Telecom Provider in a Two-Month Ramp Across Three Continents

A ransomware crew with a name borrowed from fantasy and a tracking number borrowed from a government vocabulary has spent the last two months picking off some of the most consequential targets imaginable: the operator…

Cybersecurity 1,697 words 8 min read

Warlock Ransomware Hits a Water Utility and a Telecom Provider in a Two-Month Ramp Across Three Continents — Cybersecurity No Image Cybersecurity
Lead image · Filed 5 October 2026, 04:43

Warlock Ransomware Hits a Water Utility and a Telecom Provider in a Two-Month Ramp Across Three Continents

Introduction

A ransomware crew with a name borrowed from fantasy and a tracking number borrowed from a government vocabulary has spent the last two months picking off some of the most consequential targets imaginable: the operator of a water utility and the operator of a telecommunications network. Both sit in the same category of infrastructure that security teams call critical, meaning the consequence of an outage is measured in litres of undelivered water and minutes of unreachable subscribers rather than in dollars of downtime.

The group is tracked as Warlock by several vendors, Longlegs by Symantec, Storm-2603 by Microsoft, and Gold Salem in some reporting. In a research note published on 1 October 2026, Symantec's threat hunting team documented at least four intrusions over a two-month window against organisations in Portuguese- and Spanish-speaking countries spanning Europe, Africa and Latin America. The victim list named in the report is short and specific: a water utility, a telecommunications provider, a regional government body and a university.

That mix of targets is the interesting part. Ransomware crews of Warlock's apparent calibre usually spray at whoever will pay. These four were chosen. As Dick O'Brien, principal intelligence analyst for the Symantec Threat Hunter Team, told Dark Reading, the group's recent activity "provides more questions than answers" precisely because the profile of the victims looks less like a criminal opportunistic sweep and more like intelligence collection.

Broadcom's own Warlock protection bulletin confirms the campaign and lists the detection coverage, including the file-based signature Ransom.Warlock and the behavioural signature SONAR.Ransom!gen106. This is the same reporting covered in detail by SecurityWeek and The Hacker News.

The Exploit Chain Has Not Changed, Which Is the Problem

Warlock came to prominence in mid-2025 through a chain of zero-day vulnerabilities in on-premises Microsoft SharePoint known as ToolShell. Microsoft discovered the exploitation in July 2025 and attributed it to two established state espionage groups, APT27 (also tracked as Emissary Panda, Bronze Union and Linen Typhoon) and APT31 (Zirconium, Violet Typhoon), plus one actor it could not identify. Microsoft named that third actor Storm-2603. Within weeks, more than 400 SharePoint servers were compromised. By October 2025, researchers had connected Storm-2603 to a stream of Warlock ransomware deployments against a Middle East telecommunications firm, African and South American government entities and a US university.

The chain itself is unremarkable once described. The attacker reaches an internet-facing SharePoint server, drops a web shell capable of targeting multiple SharePoint versions, and uses it to collect the SharePoint farm's ASP.NET machine keys. Those keys are then used to forge a validly signed payload, which achieves remote code execution inside the SharePoint application pool. The machine-key step is what makes this so awkward for defenders: a signed payload looks legitimate to a great deal of endpoint tooling.

What has changed over the past year is not the mechanism. It is the patience. Symantec's assessment is that ToolShell and its relatives remain a viable initial access route against SharePoint deployments that were never patched or otherwise mitigated, more than a year after the campaign became public. As of 22 July 2026, the group was still working the same path.

Six Unnamed Candidates in the Arsenal

Symantec cannot say whether the current intrusions still ride on ToolShell. The researchers point instead to a set of newer SharePoint flaws that CISA added to its Known Exploited Vulnerabilities catalog over the summer, among them CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, CVE-2026-58644, CVE-2026-50522 and CVE-2026-55040. Naming six candidates without attribution is an unusual admission from a vendor, and it is the honest one: the group's tooling cannot be confirmed against a specific flaw when the victims are a water utility and a telecom operator that will not say what they run.

O'Brien's assessment to Dark Reading was that "the exploits for these more recent vulnerabilities behave quite similarly" to ToolShell. If that holds, then the mitigations that matter are the ones already known: patch the on-premises SharePoint estate, or take it off the internet.

Two Hours, Forty Hosts, Thirty-Three Locked

The most operationally interesting detail in the reporting is not the exploit but the distribution mechanism. In one intrusion against a critical infrastructure operator, the attackers pushed a tool designed to disable security software to at least 40 hosts within roughly two hours, then deployed Warlock on at least 33 of them.

They did not do that by pushing the ransomware to each machine. Instead they staged the payload inside the domain's SYSVOL share, which Active Directory replicates automatically to every domain controller and which is readable domain-wide. Ordinary replication carried the encrypted-file binary across the estate. O'Brien called it "a bit more efficient of a living-off-the-land approach, and less well known than using tools like PsExec or Windows Management Instrumentation." That efficiency matters. It converts a deployment problem into a domain problem: the tool an attacker needs is not remote execution, it is the ability to write once to a location the domain itself will distribute on the attacker's behalf.

Living Off the Land, and Off the Developer's Tools

The rest of the tradecraft is deliberately unglamorous. The group uses DLL sideloading to load malicious code into memory and avoid leaving an executable on disk. Follow-on payloads are pulled from legitimate cloud file-sharing and storage services, with Symantec naming catbox[.]moe and wasabisys[.]com, in order to blend with normal traffic.

Security software is disabled using the bring-your-own-vulnerable-driver technique, specifically by loading a signed but exploitable driver, K7RKScan.sys, tracked as CVE-2025-1055. That same driver was previously used by DragonForce ransomware operators, which is a reminder that these fragile pieces of infrastructure in signed drivers are effectively a shared commons.

The most inventive element is the abuse of Visual Studio Code's built-in tunnel feature. Symantec observed the group installing code-insiders.exe as a service to establish covert remote network access that blends into traffic typically originating from developer or administrator workstations. A connection that looks like a developer connecting to a remote box is precisely the kind of traffic most organisations do not have the analytic capacity to challenge.

Earlier this year the group was also linked to the compromise of SmarterTools, achieved by exploiting an unpatched SmarterMail instance. Symantec notes overlaps between Warlock and older activity clusters including CL-CRI-1040, CamoFei and ChamelGang.

Why Spanish and Portuguese, and Why Now

The geographic shift is the part analysts are least able to explain. Earlier Warlock campaigns crossed Brazil, India, Japan, Russia, Taiwan and the United States, which Symantec characterised as essentially a random sampling. The current wave is confined to countries where Spanish or Portuguese is the lingua franca, but those countries span three continents.

Symantec's own framing offers two readings: either opportunistic targeting driven by exposed, vulnerable SharePoint servers, or more deliberate tasking. O'Brien offered two more in his interview: the group may have recruited members who can negotiate ransoms in those languages, or it may be exploiting a niche that other actors have not yet saturated. He also noted the broader shift, observing that "it's getting harder and harder to find soft targets in Western countries, so they're moving further afield," citing the Play group as one of the first to target Latin America in earnest before multiple groups followed.

Any of those explanations points to the same operational conclusion. The four victims were not chosen because they are unusually soft. They were chosen because they were reachable, and they were reachable through an unpatched server-side platform that has now been a known initial access route for over a year.

What Defenders Should Actually Do

The first and cheapest action remains the obvious one. On-premises SharePoint that is exposed to the internet is the attack surface here, and the mitigation is patching or removal. CISA's Known Exploited Vulnerabilities catalog is the authoritative list of the specific identifiers in question, and federal civilian agencies are already bound by its deadlines.

The second is about the domain. Because the ransomware propagates through SYSVOL, the useful question is not only "which hosts are patched" but "who can write to the SYSVOL share, and from where." An attacker who reaches one administrative workstation inherits the domain's own distribution mechanism. Monitoring SYSVOL write activity, and treating unexpected new files in the scripts portion of that share as an incident rather than a change, is a low-cost control with a direct payoff against this specific tradecraft.

The third is on the driver side. Loading of unexpected signed drivers should be logged and alerted on, because CVE-2025-1055 is a known-abused driver and its use here is documented rather than theoretical.

The fourth is about egress and the endpoint. Living-off-the-land techniques succeed because the tooling is legitimate. An outbound tunnel from a server, and specifically from a machine running a developer tool in a server context, deserves scrutiny.

Conclusion

The uncomfortable part of the Warlock story is not that the tooling is novel. DLL sideloading, BYOVD, living-off-the-land execution and domain replication are all well-established techniques that security teams have defended against for years. The uncomfortable part is that a group first observed exploiting SharePoint zero-days in July 2025 is still succeeding in October 2026 against water and telecommunications operators, and that the vendor responsible for the most detailed public analysis cannot say which of six candidate vulnerabilities is being used.

Symantec's own conclusion is the one worth carrying forward: continued activity more than a year after Warlock first appeared "shows that exploitation of ToolShell and other related-SharePoint vulnerabilities remains a viable initial access route for attackers on SharePoint deployments that have not been patched or otherwise mitigated." That is a statement about unfinished work, not about novel threat intelligence. For organisations running on-premises SharePoint, the shortest path to not being in the next paragraph of this story is the one that has been available since July 2025.

For further coverage of intrusions, patching and detection engineering, see our ongoing cybersecurity reporting.

Images

Industrial water treatment process hall with blue-painted steel framework, extensive process piping and enclosed filter housings. This is a US Army Corps of Engineers photograph from 2015 of the Fort Irwin Water Treatment Plant during its construction and commissioning phase, taken on a US military water system — it is not one of the Warlock victims and no incident is depicted. Public domain, via Wikimedia Commons.

A silver-grey telecommunications monopole mast carrying antenna and microwave equipment units, photographed against a clear blue sky with no ground or buildings in frame. Illustrative of the kind of transmission infrastructure a telecom operator runs, not an attacked site. Photo: Wainuio, CC BY-SA 4.0, via Wikimedia Commons.

The top of an antenna mast on the slopes of Slieve Mish above Tralee Bay in County Kerry, with a cargo ship at Fenit harbour visible across the water. Illustrative landscape shot of transmission infrastructure, unrelated to the Warlock campaign. Photo: Maoileann, CC BY-SA 4.0, via Wikimedia Commons.

References