News Room
16
Share
Global Critical Infrastructure Under Siege: 'Warlock' Ransomware Group Targets Utilities via SharePoint Exploits
criticalCritical Infrastructure

Global Critical Infrastructure Under Siege: 'Warlock' Ransomware Group Targets Utilities via SharePoint Exploits

A China-nexus threat actor, tracked as Longlegs (Storm-2603), is actively exploiting SharePoint vulnerabilities to compromise water and telecommunications operators across three continents.

₿

Encrygma is selling the entire Full Cyber Weapon Research of Global Critical Infrastructure Under Siege: 'Warlock' Ransomware Group Targets Utilities via SharePoint Exploits for ₿ 0.10 BTC. Contact us.

06 October 2026Last updated 06 October 20264 min readSymantec Threat Hunter Team
E
Encrygma AI Cyber Weapons Advisory Services : ₿ 0.10 BTCWe sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram

Executive Takeaway — TL;DR

Category:
Critical Infrastructure
Severity:
Critical
Actor Type:
APT
Geography:
Global
Confidence:
Confirmed
Source:
Symantec Threat Hunter Team
Read Time:
4 min

Executive Summary

In the last 48 hours, intelligence reports have confirmed an escalating campaign by the China-nexus threat actor known as 'Longlegs' (also tracked as Storm-2603). The group is leveraging a series of Microsoft SharePoint vulnerabilities, including both legacy 'ToolShell' exploits and newer flaws, to breach critical infrastructure operators. Victims identified in this recent wave of activity include water utilities and telecommunications providers across Europe, Africa, and Latin America, signaling a deliberate shift toward targeting essential services.

Threat Analysis

The Longlegs group demonstrates a high level of operational discipline, favoring initial access through public-facing SharePoint servers that remain unpatched against both 2025 and 2026 vulnerabilities. Once inside, the group conducts extensive lateral movement and reconnaissance, often blending their malicious traffic with legitimate administrator or developer activity to evade detection. The primary objective appears to be the deployment of 'Warlock' ransomware, which has been observed systematically disabling security software before paralyzing host systems.

Technical Details

The attack chain typically begins with the exploitation of SharePoint zero-days or known vulnerabilities. Upon establishing a foothold, the actors use a custom tool to disable endpoint protection across dozens of hosts simultaneously. In recent intrusions, the attackers have been observed staging the Warlock ransomware in the domain's SYSVOL share, allowing for rapid, automated distribution via standard domain replication processes. Furthermore, researchers have noted the abuse of signed drivers (specifically K7RKScan) and Visual Studio Code's tunneling feature to maintain persistent, covert remote access.

Attribution Assessment

The campaign is definitively attributed to Longlegs (Storm-2603), a China-nexus group that first gained notoriety in mid-2025. Their persistence in using specific SharePoint exploit chains and their evolving toolset—including the use of tunneling features for persistence—suggests a well-resourced actor with a long-term strategic interest in compromising critical infrastructure operational technology (OT) and information technology (IT) environments.

Implications

The successful targeting of water utilities and telecommunications firms poses a severe risk to public health and national stability. The ability of these actors to disable security software and move laterally at speed indicates that many critical infrastructure environments remain inadequately segmented. The reliance on legacy systems, combined with unpatched edge services, continues to be a primary vector that threat actors are exploiting to gain maximum impact.

Recommendations

  1. Immediate Patching: Prioritize patching all SharePoint deployments against current known vulnerabilities.
  2. Network Segmentation: Implement rigorous network segmentation to isolate IT management systems from OT environments, preventing lateral movement in the event of an IT breach.
  3. Credential Hygiene: Remove default credentials from all industrial control systems and enforce multi-factor authentication (MFA) across all administrative interfaces.
  4. Monitor SYSVOL: Audit and monitor the SYSVOL share for unauthorized staging of executables or binaries, as this has become a preferred distribution method for the Warlock group.
  5. Visibility: Enhance telemetry and monitoring of edge appliances to detect suspicious tunneling or unauthorized service execution.
Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo