Enterprise Cybersecurity IntelligenceMonday

An enterprise cybersecurity intelligence company.For security and technology leaders.

Security.io Intelligence

What changed, why it matters,
and how it evolved.

Ransomware · Executive briefing

Warlock keeps turning SharePoint debt into critical-sector ransomware

New research shows Warlock still converting exposed on-premises SharePoint into ransomware access, including at water and telecommunications organisations.

RansomwareVulnerability ManagementIncident Response
Why it is in today’s brief

ToolShell and Warlock are older issues; the new October 2 research documents continued success against four organisations, including water and telecommunications operators, with quantified endpoint-control suppression and ransomware deployment. It warrants inclusion because the enterprise decision changed from confirming patches to reconstructing historical exposure, rotating machine keys and proving domain-level recovery.

Read first

Symantec and Carbon Black research, reported Friday, described Warlock ransomware activity against four organisations over the preceding two months.

Act now

Identify every on-premises SharePoint server and reconstruct historical internet exposure.

Accountable owner

CISO with infrastructure, identity and incident-response leaders

Decision horizon

Today through 48 hours: validate SharePoint compromise status, machine-key rotation and domain-level ransomware readiness.

AssessmentMedium confidence
Emerging riskWatch for named victim confirmations, updated indicators, evidence of broader regional targeting, additional initial-access vulnerabilities or findings that connect the campaign to OT impact or confirmed data theft.

What happened

Microsoft patched the ToolShell SharePoint Server chain, CVE-2025-49704, CVE-2025-49706, CVE-2025-53770 and CVE-2025-53771, in July 2025; SharePoint Online is not affected.

On October 2, 2026, reporting based on new Symantec and Carbon Black research described continuing Warlock intrusions through on-premises SharePoint vulnerabilities.

Across the two months before publication, researchers identified at least four affected organisations: a water utility, a telecommunications provider, a regional government body and a university in Portuguese- and Spanish-speaking countries across Europe, Africa and Latin America.

In one detailed intrusion, the attackers disabled protection software on at least 40 hosts in about two hours, deployed Warlock ransomware to 33 hosts through the domain SYSVOL share and took nine days from initial access to the final stage. The reported chain included SharePoint web shells, theft of ASP.NET machine keys, Visual Studio Code tunnelling, a vulnerable K7RKScan driver used to suppress endpoint protection and ransomware staging through SYSVOL. The activity demonstrates that remediation must address retained cryptographic and identity material, not only installed SharePoint updates. The cited weekend reporting did not publish victim names, incident-specific hashes, IP addresses, domains, ransom-payment outcomes or confirmed data-exfiltration findings.

Why this matters now

The vulnerabilities are not new; the decision-changing evidence is that a ransomware operator continues to gain access through them more than a year after patches became available. That turns old remediation debt into a current incident-exposure question, particularly for critical services with long-lived on-premises SharePoint deployments.

The reported sequence reaches beyond the initial web server. Web shells, stolen ASP.NET machine keys, tunnelling, security-tool suppression and SYSVOL staging create routes into identity and domain operations. A patched SharePoint server can remain unsafe if attackers retained machine keys, persistence, credentials or administrative footholds from earlier access.

The affected sectors include water, telecommunications, regional government and education across multiple regions. The sources did not report OT disruption, named victims or ransom outcomes, so leadership should avoid assuming sector-wide compromise while still prioritising exposed SharePoint and recovery dependencies.

The decision for security leaders

Do not accept current patch status as compromise closure. Infrastructure and incident-response teams should establish whether each historically exposed SharePoint server received machine-key rotation, web-shell review, identity containment and sufficient log analysis after ToolShell remediation.

Prioritise organisations with public SharePoint, weak endpoint visibility or critical service dependencies. The campaign’s path from a web application to domain-wide ransomware means the decision owner spans application infrastructure, Active Directory, endpoint security and resilience rather than a single server team.

Validate recovery assumptions against deliberate security-tool suppression and SYSVOL abuse. Recovery plans should identify how domain services, file distribution and endpoint rebuilding continue if shared administrative paths are untrusted.

Evidence of closure

  • Asset record proves every on-premises SharePoint farm, version, owner and historical exposure.
  • Validation report confirms ToolShell fixes, machine-key rotation and web-shell review.
  • Hunt results document driver, tunnel, SYSVOL and endpoint-control evidence across retained telemetry.
  • Recovery exercise proves critical services can resume without affected SharePoint or domain distribution paths.

The Security.io assessment

The evidence does not describe a new ToolShell disclosure. It demonstrates continued operational exploitation of old SharePoint weaknesses against organisations that include critical services. That makes historical exposure and post-patch compromise review the material Monday question.

The reported counts show rapid defensive impairment once domain access was established. They do not establish how broadly the campaign operates, whether all four organisations suffered encryption or whether any water or telecommunications operations were disrupted.

Attribution posture: Symantec tracks the operator as Longlegs, Microsoft tracks it as Storm-2603, and the reporting describes a China-linked nexus.

Security.io assigns medium confidence because the campaign chronology and technical sequence originate with established research teams and accountable reporting, but victims remain unnamed and incident-specific indicators, exfiltration findings and operational consequences were not published.

Questions for the morning meeting

  • Which on-premises SharePoint servers remain internet-reachable or retain historical exposure?
  • Were ASP.NET machine keys rotated after ToolShell remediation?
  • Can recovery isolate SYSVOL and preserve domain operations if ransomware staging is detected?

Related intelligence

Shared decision context