
Global Critical Infrastructure Under Siege: 'Warlock' Ransomware Group Targets Utilities via SharePoint Exploits
A China-nexus threat actor, tracked as Longlegs (Storm-2603), is actively exploiting SharePoint vulnerabilities to compromise water and telecommunications operators across three continents.
Encrygma is selling the entire Full Cyber Weapon Research of Global Critical Infrastructure Under Siege: 'Warlock' Ransomware Group Targets Utilities via SharePoint Exploits for ₿ 0.10 BTC. Contact us.
Executive Takeaway — TL;DR
- Category:
- Critical Infrastructure
- Severity:
- Critical
- Actor Type:
- APT
- Geography:
- Global
- Confidence:
- Confirmed
- Source:
- Symantec Threat Hunter Team
- Read Time:
- 4 min
Executive Summary
In the last 48 hours, intelligence reports have confirmed an escalating campaign by the China-nexus threat actor known as 'Longlegs' (also tracked as Storm-2603). The group is leveraging a series of Microsoft SharePoint vulnerabilities, including both legacy 'ToolShell' exploits and newer flaws, to breach critical infrastructure operators. Victims identified in this recent wave of activity include water utilities and telecommunications providers across Europe, Africa, and Latin America, signaling a deliberate shift toward targeting essential services.
Threat Analysis
The Longlegs group demonstrates a high level of operational discipline, favoring initial access through public-facing SharePoint servers that remain unpatched against both 2025 and 2026 vulnerabilities. Once inside, the group conducts extensive lateral movement and reconnaissance, often blending their malicious traffic with legitimate administrator or developer activity to evade detection. The primary objective appears to be the deployment of 'Warlock' ransomware, which has been observed systematically disabling security software before paralyzing host systems.
Technical Details
The attack chain typically begins with the exploitation of SharePoint zero-days or known vulnerabilities. Upon establishing a foothold, the actors use a custom tool to disable endpoint protection across dozens of hosts simultaneously. In recent intrusions, the attackers have been observed staging the Warlock ransomware in the domain's SYSVOL share, allowing for rapid, automated distribution via standard domain replication processes. Furthermore, researchers have noted the abuse of signed drivers (specifically K7RKScan) and Visual Studio Code's tunneling feature to maintain persistent, covert remote access.
Attribution Assessment
The campaign is definitively attributed to Longlegs (Storm-2603), a China-nexus group that first gained notoriety in mid-2025. Their persistence in using specific SharePoint exploit chains and their evolving toolset—including the use of tunneling features for persistence—suggests a well-resourced actor with a long-term strategic interest in compromising critical infrastructure operational technology (OT) and information technology (IT) environments.
Implications
The successful targeting of water utilities and telecommunications firms poses a severe risk to public health and national stability. The ability of these actors to disable security software and move laterally at speed indicates that many critical infrastructure environments remain inadequately segmented. The reliance on legacy systems, combined with unpatched edge services, continues to be a primary vector that threat actors are exploiting to gain maximum impact.
Recommendations
- Immediate Patching: Prioritize patching all SharePoint deployments against current known vulnerabilities.
- Network Segmentation: Implement rigorous network segmentation to isolate IT management systems from OT environments, preventing lateral movement in the event of an IT breach.
- Credential Hygiene: Remove default credentials from all industrial control systems and enforce multi-factor authentication (MFA) across all administrative interfaces.
- Monitor SYSVOL: Audit and monitor the SYSVOL share for unauthorized staging of executables or binaries, as this has become a preferred distribution method for the Warlock group.
- Visibility: Enhance telemetry and monitoring of edge appliances to detect suspicious tunneling or unauthorized service execution.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Spanish Rail Infrastructure Breach: Adif Web Systems Exploited to Compromise Renfe Operations

Japanese Railway Infrastructure Targeted in Coordinated Cyber-Espionage Campaign

