Warlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical Infrastructure
Warlock ransomware operators still exploit unpatched SharePoint flaws to hit water, telecom, government, and university targets.
Symantec says the Warlock ransomware group, tracked as Longlegs and Storm-2603, is still exploiting unpatched Microsoft SharePoint ToolShell flaws more than a year after they emerged. In two months it hit at least four organizations—a water utility, a telecom provider, a regional government body, and a university—in Portuguese- or Spanish-speaking countries. Attackers planted a webshell, stole ASP.NET machine keys, sideloaded DLLs, abused Visual Studio Code tunneling, and used the signed K7RKScan driver to disable security tools. In one critical-infrastructure intrusion beginning 22 July 2026, they disabled defenses on at least 40 hosts and deployed Warlock to at least 33 through SYSVOL replication.