MediumII Cyber Warfare & Critical Infrastructure1 October 2026, Thursday
China-linked Warlock hits water and telecom firms through SharePoint flaws
Symantec and Carbon Black said on 1 October that the China-linked Longlegs group (Storm-2603) has infected 4 organisations with Warlock ransomware over the past 2 months. The targets include 1 water utility and 1 telecoms provider.
According to Symantec's report of 1 October, the attacks clustered in Portuguese- and Spanish-speaking countries in Europe, Africa and Latin America, though the victims' countries were not disclosed. Besides the 2 critical infrastructure operators, the victims include 1 regional government body and 1 university. The location on the map is indicative; the countries of the 4 victims are unknown. One documented attack began on 22 July with a web shell planted on a SharePoint server and ended on 31 July with the deployment of ransomware, a span of about 9–10 days.
The group continues to exploit 4 SharePoint flaws known as 'ToolShell' from mid-2025 (CVE-2025-49704, -49706, -53770, -53771). According to BleepingComputer, the attackers loaded a vulnerable driver (CVE-2025-1055) with their own tools and disabled security software on at least 40 computers in about 2 hours. Ransomware was then deployed to at least 33 computers. According to The Hacker News, the group is using legitimate Visual Studio Code tunnels for command and control in its 2026 attacks.
Symantec describes Longlegs as a China-linked actor overlapping with 3 activity clusters: CL-CRI-1040, CamoFei and ChamelGang. Patches for the ToolShell flaws have been available since July 2025. That the attacks continue in 2026 shows unpatched on-premises SharePoint servers remain widespread.
Talay assessment
Bottom line
The report shows a China-linked group blurring the line between espionage and ransomware while targeting critical infrastructure. The attacks run not through a new flaw but through the ToolShell vulnerabilities patched in 2025, so the constraint is not technical but the number of unpatched on-premises servers. The most likely course is that the group spreads the same method to new language and regional clusters.
Likely effects
- Water and telecom operatorsNegativeWeeks
Infrastructure operators running on-premises SharePoint remain exposed to attacks that can switch off security software within hours.
- Cyber insuranceNegative1–6 months
Ransomware attacks on critical infrastructure will lead insurers to tighten patch-level requirements and premiums.
- Public servers in TürkiyeNegativeWeeks
The continued exploitation of flaws patched since 2025 makes patch audits urgent for Turkish public bodies running on-premises SharePoint.
Possibilities, ranked
- 1Attacks spread55%
The group applies the same chain to unpatched servers in other countries, and new victims are disclosed.
Watch: A new critical infrastructure victim posted on the Warlock leak site
- 2An official warning follows30%
CISA or European cyber agencies issue a joint warning on the SharePoint and driver flaws.
Watch: CISA adding CVE-2025-1055 to its Known Exploited Vulnerabilities (KEV) list
- 3Activity dies down15%
After the report, the group changes its infrastructure and stays quiet for a few months.
Watch: No new Warlock incidents in security firms' reports
Probabilities are calibrated judgement based on the sources, not measurement, and are revised as new information arrives. Not investment advice.
Market reaction
Indicators affected
- Devices with security tools disabled▼ 40+
- Devices hit by ransomware▼ 33+
- Victim organisations in 2 months▼ 4