Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Lula and Bolsonaro Face Off in Brazilian Election

    October 3, 2026

    Pentagon’s new Office of Religious Affairs under Hegseth: What we know

    October 3, 2026

    G7 to release 100 million barrels of oil and diesel after Trump export ban threat

    October 3, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Lula and Bolsonaro Face Off in Brazilian Election
    • Pentagon’s new Office of Religious Affairs under Hegseth: What we know
    • G7 to release 100 million barrels of oil and diesel after Trump export ban threat
    • What is Zionism and why do some critics describe it as racist? | Israel
    • Tories pledge to build 50,000 new prison places
    • Rivian’s sales pop as the company’s big R2 bet starts to pay off
    • IBM Brings Bob to Self-Hosted and Air-Gapped Environments: Agentic Software Development Without Moving Your Code
    • GitLab warns of critical RCE vulnerability in AI Gateway service
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Saturday, October 3
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Warlock ransomware breach SharePoint in water, telecom operator attacks

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKOctober 3, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    The China-linked ransomware group Warlock targeted a water utility, a telecom provider, a regional government body, and a university by exploiting SharePoint vulnerabilities to gain initial access.

    ​Over the past two months, the threat actor appears to have focused on countries speaking Portuguese and Spanish across Europe, Africa, and Latin America.

    The gang emerged in June 2025 and gained notoriety a month later after exploiting a chain of zero-day vulnerabilities in Microsoft SharePoint known as ToolShell (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771).

    By August, Microsoft observed state-backed hacking groups Linen Typhoon and Violet Typhoon using ToolShell exploits in attacks, along with a ransomware threat actor the company tracks as Storm-2603.

    EDR killer deployed to 40 hosts

    Cybersecurity company Symantec identifies the same actor as Longlegs and attributes the development of the Warlock ransomware to the group.

    According to the researchers, in one intrusion that started on July 22, the threat actor deployed a tool that disabled protection software on “at least 40 hosts within about two hours.” The attacker then launched Warlock ransomware on at least 33 hosts.

    After gaining access, typically by exploiting vulnerabilities in on-premises SharePoint deployments, the attacker drops a web shell designed to function across multiple SharePoint versions.

    Symantec and Carbon Black researchers say that in some attacks attributed to Longlegs, an AV/EDR-killing tool was deployed via the bring your own vulnerable driver (BYOVD) technique using a signed K7RKScan driver vulnerable to CVE-2025-1055.

    Analysis of the intrusion on July 22 revealed that two days after gaining initial access, the threat actor engaged in reconnaissance activity and deleted what seemed like staging artifacts.

    Using VS Code’s tunneling capability

    The ransomware payload was staged in the domain’s SYSVOL share, a location that stores public files and is replicated across every domain controller.

    This is “a known method of pushing a payload out for execution by a logon script or Group Policy object across an entire network at once, rather than one host at a time,” the researchers say.

    During the attack, the main executable file for Visual Studio Code Insiders was installed as a service to enable connecting remotely to compromised machines using VS Code’s built-in tunneling capability.

    On one of the systems, the researchers found the open-source penetration testing framework NetExec, which helped the attacker with Active Directory enumeration, credential spraying, and remote command execution.

    The final stage of the attack occurred on July 31st, after deploying the AV/EDR killer, with Warlock ransomware “appearing almost as soon as protection was disabled on each host.”

    The researchers warn that ToolShell and other SharePoint vulnerabilities remain viable initial access vectors, more than a year after Warlock first emerged exploiting SharePoint flaws.

    The report from the Symantec and Carbon Black threat hunters includes a set of indicators of compromise for files and infrastructure used in the attacks.


    article image

    Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

    Save your seat

    attacks breach operator ransomware SharePoint Telecom Warlock water
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    GitLab warns of critical RCE vulnerability in AI Gateway service

    Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes

    AI Agents Aimed SQL Injection at US and Canadian Government Sites

    Why CISOs Struggle to Answer the Board’s Three Hardest Questions, and How to Fix the Report

    Frontline Education breach exposes school district employee data

    Warlock Expands SharePoint Exploitation in Critical Infrastructure Attacks

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Lula and Bolsonaro Face Off in Brazilian Election

    October 3, 2026

    Pentagon’s new Office of Religious Affairs under Hegseth: What we know

    October 3, 2026

    G7 to release 100 million barrels of oil and diesel after Trump export ban threat

    October 3, 2026

    What is Zionism and why do some critics describe it as racist? | Israel

    October 3, 2026
    Latest Posts

    Lime bikes hurtling around the city: is this the revenge of a priced-out generation? | Andy Beckett

    August 8, 2026

    Clarity Act Delayed Until September, Trump Praises Bitcoin

    August 8, 2026

    North Carolina Ports confirms cyberattack disrupting operations

    August 8, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Lula and Bolsonaro Face Off in Brazilian Election

    October 3, 2026

    Pentagon’s new Office of Religious Affairs under Hegseth: What we know

    October 3, 2026

    G7 to release 100 million barrels of oil and diesel after Trump export ban threat

    October 3, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.