The China-linked ransomware group Warlock (also tracked as Gold Salem, Longlegs and Storm-2603) has, over the past two months, attacked at least four organisations by exploiting Microsoft SharePoint vulnerabilities for initial access — including two critical-infrastructure operators (a water utility and a telecommunications provider), a regional government body and a university, according to Symantec's Carbon Black Threat Hunter Team. Victims were in Portuguese- and Spanish-speaking countries across Europe, Africa and Latin America. Symantec detailed one intrusion against a critical-infrastructure operator starting 22 July in which the attackers pushed a tool that disabled security software on at least 40 hosts within about two hours, then deployed Warlock on at least 33 hosts by staging it in the domain's SYSVOL share, where ordinary domain replication delivered it to machines; AV/EDR-killing used the bring-your-own-vulnerable-driver technique with a driver vulnerable to CVE-2025-1055. Warlock previously exploited the ToolShell SharePoint zero-day chain in mid-2025. The campaign is a clear sign China-linked actors are actively weaponising SharePoint flaws against utilities and other critical infrastructure.
| Attribute | Detail |
|---|---|
| Sector | Energy & Utilities |
| Date | 2026-10-04 |
| Source | The Hacker News |
| Reliability | Tier 2 |
| CVEs | CVE-2025-1055 |