Skip to content
RegionAmericas

MediumII Cyber Warfare & Critical Infrastructure1 October 2026, Thursday

China-linked Warlock hits water and telecom firms through SharePoint flaws

Symantec and Carbon Black said on 1 October that the China-linked Longlegs group (Storm-2603) has infected 4 organisations with Warlock ransomware over the past 2 months. The targets include 1 water utility and 1 telecoms provider.

Location: LATIN AMERICA

According to Symantec's report of 1 October, the attacks clustered in Portuguese- and Spanish-speaking countries in Europe, Africa and Latin America, though the victims' countries were not disclosed. Besides the 2 critical infrastructure operators, the victims include 1 regional government body and 1 university. The location on the map is indicative; the countries of the 4 victims are unknown. One documented attack began on 22 July with a web shell planted on a SharePoint server and ended on 31 July with the deployment of ransomware, a span of about 9–10 days.

The group continues to exploit 4 SharePoint flaws known as 'ToolShell' from mid-2025 (CVE-2025-49704, -49706, -53770, -53771). According to BleepingComputer, the attackers loaded a vulnerable driver (CVE-2025-1055) with their own tools and disabled security software on at least 40 computers in about 2 hours. Ransomware was then deployed to at least 33 computers. According to The Hacker News, the group is using legitimate Visual Studio Code tunnels for command and control in its 2026 attacks.

Symantec describes Longlegs as a China-linked actor overlapping with 3 activity clusters: CL-CRI-1040, CamoFei and ChamelGang. Patches for the ToolShell flaws have been available since July 2025. That the attacks continue in 2026 shows unpatched on-premises SharePoint servers remain widespread.

Talay assessment

Bottom line

The report shows a China-linked group blurring the line between espionage and ransomware while targeting critical infrastructure. The attacks run not through a new flaw but through the ToolShell vulnerabilities patched in 2025, so the constraint is not technical but the number of unpatched on-premises servers. The most likely course is that the group spreads the same method to new language and regional clusters.

Likely effects

  • Water and telecom operatorsNegativeWeeks

    Infrastructure operators running on-premises SharePoint remain exposed to attacks that can switch off security software within hours.

  • Cyber insuranceNegative1–6 months

    Ransomware attacks on critical infrastructure will lead insurers to tighten patch-level requirements and premiums.

  • Public servers in TürkiyeNegativeWeeks

    The continued exploitation of flaws patched since 2025 makes patch audits urgent for Turkish public bodies running on-premises SharePoint.

Possibilities, ranked

  1. 1
    Attacks spread55%

    The group applies the same chain to unpatched servers in other countries, and new victims are disclosed.

    Watch: A new critical infrastructure victim posted on the Warlock leak site

  2. 2
    An official warning follows30%

    CISA or European cyber agencies issue a joint warning on the SharePoint and driver flaws.

    Watch: CISA adding CVE-2025-1055 to its Known Exploited Vulnerabilities (KEV) list

  3. 3
    Activity dies down15%

    After the report, the group changes its infrastructure and stays quiet for a few months.

    Watch: No new Warlock incidents in security firms' reports

Probabilities are calibrated judgement based on the sources, not measurement, and are revised as new information arrives. Not investment advice.

Market reaction

Indicators affected

  • Devices with security tools disabled▼ 40+
  • Devices hit by ransomware▼ 33+
  • Victim organisations in 2 months▼ 4

Sources

  1. Symantec (security.com) — Warlock Ransomware Attackers Hit Water and Telecom Operators
  2. BleepingComputer — Warlock ransomware breach SharePoint in water, telecom operator attacks
  3. The Hacker News — Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware