Skip to content
Brief Security & Trust ·

Warlock ransomware group hits water and telecom firms through SharePoint

Symantec says a China-linked group attacked at least four organizations in two months.

In brief
  • Symantec says the group behind Warlock attacked at least four organizations in two months, including a water utility and a telecom provider. It got in through SharePoint flaws.
  • In one attack, activity began July 22 and Warlock ran on at least 33 machines on July 31. The sources do not name the victims.

Symantec said a China-linked group it calls Longlegs, also tracked as Storm-2603, built Warlock ransomware. It says the group attacked at least four organizations in the past two months. BleepingComputer covered the findings on October 2. Two of the victims, a water utility and a telecom provider, run essential services. The others were a university and a regional government body. All were in Portuguese- or Spanish-speaking countries across Europe, Africa and Latin America. In one attack, activity began July 22. The final phase came July 31, when a tool to switch off security software ran on at least 40 hosts within about two hours. Warlock then ran on at least 33.

Symantec said the group gets in through SharePoint servers that organizations run themselves. A planted web page collects the server's machine keys. Those keys let attackers forge validly signed requests and run code. The ransomware sat in SYSVOL, a shared Windows folder copied across a network, so ordinary copying delivered it. Symantec said the driver used to disable security tools in the July attack is unknown. In other attacks, it was K7RKScan, a signed but flawed driver. Symantec said the country focus could be chance or deliberate targeting.

This attack works by using parts of a network that are trusted: keys the server accepts, a signed driver, and Windows' own copying. Symantec said SharePoint servers left unpatched or unmitigated remain open to the ToolShell flaws. Teams running SharePoint should confirm fixes are applied and test whether their security tools survive a driver-based shutdown.

A WebPulse Brief: a short report of an important event, written by the WebPulse Newsroom with AI assistance and checked against the reporting below. When there is more to explain, we follow up with a full story. How we use AI.

Reporting: security.com.