
🚨 #ALERT — WARLOCK RANSOMWARE CAMPAIGN HITS WATER AND TELECOM OPERATORS THROUGH SHAREPOINT October 1, 2026 DISCLOSED BY: Symantec / Carbon Black CONFIRMED EXPLOITED BY: Symantec / Carbon Black PRODUCT: Microsoft SharePoint Server — On-Premises CVE: Multiple SharePoint vulnerabilities are used across the campaign. Historically associated ToolShell flaws include CVE-2025-49704, CVE-2025-49706, CVE-2025-53770 and CVE-2025-53771. IMPACT: Symantec documented a recent Warlock campaign compromising at least four organizations, including a water utility and telecommunications provider, plus a regional government body and university. In one critical-infrastructure intrusion, attackers disabled security tooling on at least 40 hosts in roughly two hours and deployed Warlock ransomware to at least 33 systems through the domain SYSVOL share. EXPLOITATION STATUS: CONFIRMED OPERATIONAL RANSOMWARE CAMPAIGN CISA records knownRansomwareCampaignUse: Known for the core ToolShell KEV entries CVE-2025-49704, CVE-2025-49706 and CVE-2025-53770. The exact SharePoint CVE used for every recent intrusion has NOT been established. Attribution: Symantec tracks the actor as Longlegs, also associated with Storm-2603, and assesses it as China-nexus. This is NOT a formal government attribution to the Chinese state. Forensic triage: Hunt for SharePoint LAYOUTS web shells, stolen http://ASP.NET machine keys, K7RKScan/BYOVD activity, Visual Studio Code tunnels, NetExec, suspicious SYSVOL payloads and domain-wide ransomware staging. URGENT ACTION: Patch all on-premises SharePoint servers. Previously exposed systems require compromise assessment, http://ASP.NET machine-key rotation, credential review, and hunting across SYSVOL and domain controllers; patching alone does not establish that the environment is clean. SOURCE: https://www.security.com/threat-intelligence/warlock-ransomware-critical-infrastructure CISA: https://www.cisa.gov/known-exploited-vulnerabilities-catalog BACKUP: https://raw.githubusercontent.com/cisagov/kev-data/develop/known_exploited_vulnerabilities.json?utm_source=chatgpt.com CONFIDENCE: VERY HIGH for the campaign, victim scope and observed post-exploitation behavior based on direct Symantec/Carbon Black investigations. The China-nexus attribution is a vendor intelligence assessment, not a formal government attribution. #CyberSecurity #ThreatIntel #NØØT #Microsoft #SharePoint #ToolShell #Warlock #Storm2603 #Ransomware #ActiveExploitation #CriticalInfrastructure #IncidentResponse #DigitalForensics


