(TLP:CLEAR) Warlock Ransomware Hits Water Utility Among Spanish- and Portuguese-Speaking Targets
Created: Thursday, October 8, 2026 - 15:10
Categories: Cybersecurity, Security Preparedness
Summary: The China-nexus group behind Warlock ransomware has shifted its focus to organizations in Spanish- and Portuguese-speaking countries, and a water utility is among its recent victims. According to reporting from Symantec, the group (tracked as Longlegs and Storm-2603) hit at least four organizations across Europe, Africa, and Latin America over the past two months: a water utility, a telecommunications provider, a regional government body, and a university. The targeting reflects a move toward fewer, yet higher-value victims.
Warlock gains initial access by exploiting Microsoft SharePoint vulnerabilities, originally through the exploit chain known as ToolShell and more recently through similar SharePoint flaws added to CISA’s Known Exploited Vulnerabilities (KEV) catalog. After entry, it uses DLL sideloading, a vulnerable signed driver to disable security tools, and living-off-the-land techniques. Its notable tactic is staging the ransomware in the domain’s SYSVOL share so that normal Active Directory replication distributes the payload to every domain controller.
Analyst Note: A confirmed water utility victim, combined with a SharePoint entry vector, makes this directly relevant to the sector. Warlock’s initial access depends on the ToolShell exploit chain, which is a set of on-premises SharePoint Server vulnerabilities tracked as CVE-2025-49704 and CVE-2025-49706, along with their patch-bypass variants CVE-2025-53770 and CVE-2025-53771. All are listed in CISA’s Known Exploited Vulnerabilities (KEV) catalog, and Symantec notes that more recent SharePoint flaws behave similarly. These vulnerabilities affect on-premises SharePoint only, not SharePoint Online in Microsoft 365. WaterISAC covered ToolShell when it emerged in its advisory, Critical Vulnerabilities in On-Premises SharePoint Server Actively Exploited, and Warlock’s current campaign shows the same vulnerabilities are still being turned into ransomware more than a year later.
The SYSVOL replication technique is the detail worth the most attention. By staging the payload in a domain controller’s SYSVOL share, Warlock lets normal Active Directory replication carry the ransomware to every domain controller, rather than pushing it host by host with tools like PsExec or WMI. That approach is quieter and can slip past detections tuned for the more common remote-execution methods, which means a single compromised domain controller can become domain-wide encryption.
WaterISAC encourages members running on-premises SharePoint to confirm their servers are patched against the four ToolShell CVEs above, and to treat any internet-facing SharePoint that was exposed before patching as potentially compromised. Beyond patching, members can monitor domain controllers and SYSVOL for unexpected changes and restrict remote tunneling tools such as VS Code’s tunneling feature where they are not needed.
Original Source: https://www.broadcom.com/support/security-center/protection-bulletin/warlock-ransomware-targets-water-and-telecom-operators
Additional Reading:
- Warlock Ransomware Hits Large Spanish, Portuguese Orgs
- (TLP:CLEAR) WaterISAC Advisory – ACTION MAY BE REQUIRED: Critical Vulnerabilities in On-Premises SharePoint Server Actively Exploited (Updated October 23, 2025)
Related WaterISAC PIRs: 6, 7, 7.1, 8, 10, 12
