Warlock ransomware breach SharePoint in water, telecom operator attacks
Warlock ransomware exploited SharePoint ToolShell flaws to hit a water utility, telecom, government body, and university.
The China-linked Warlock ransomware group, tracked by Symantec as Longlegs and related to Microsoft's Storm-2603, attacked a water utility, a telecom provider, a regional government body, and a university. Initial access came from on-premises Microsoft SharePoint ToolShell flaws CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771, followed by a web shell. In a July 22 intrusion, the actor used a BYOVD EDR killer leveraging a signed K7RKScan driver (CVE-2025-1055) on at least 40 hosts, staged Warlock in SYSVOL, abused Visual Studio Code tunneling and NetExec, and encrypted at least 33 hosts on July 31.