malware
Published 2026-10-01
Verified 2026-10-03

Symantec (1 Oct): Warlock / Longlegs (Storm-2603) still hitting SharePoint — water & telecom CI in PT/ES-speaking countries

Broadcom Symantec Threat Intelligence (1 October 2026; SecurityWeek amplify 2 Oct) reports the China-nexus operator behind Warlock ransomware — tracked by Symantec as Longlegs (aka Storm-2603; linked to CL-CRI-1040 / CamoFei / ChamelGang) — continues exploiting Microsoft SharePoint flaws against critical infrastructure, government and education. Past two months: at least four victim organisations in Portuguese- and Spanish-speaking countries spanning Europe, Africa and Latin America, including a water utility, a telecommunications provider, a regional government body and a university. One intrusion disabled security software on ≥40 systems then ran Warlock on ≥33. Typical chain after SharePoint access: webshell, ASP.NET machine-key theft, forced-signed RCE payload; DLL sideloading / LOTL; abuse of legitimate file-sharing hosts and a vulnerable driver to blunt EDR. Warlock rose on the 2025 ToolShell SharePoint exploit chain; Symantec notes arsenal may also include newer SharePoint CVEs (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, CVE-2026-58644, CVE-2026-50522, CVE-2026-55040). No Australian victim named in this report. Primary: Symantec/security.com; wire: SecurityWeek 2 Oct.

Product
Microsoft SharePoint Server (on-prem) — ToolShell and later SharePoint flaws abused for Warlock ransomware initial access
Versions
n/a (campaign; patch/mitigate exposed SharePoint per Microsoft guidance; ToolShell chain historically CVE-class SharePoint RCE/auth bypass set)
Exploited in Australia?
unknown
Patch to
Ensure on-prem SharePoint is fully patched against ToolShell-era and 2026 SharePoint CVEs cited by Symantec; hunt webshells / stolen ASP.NET machine keys; review EDR tamper and vulnerable-driver BYOVD indicators from the Symantec report.

Primary: Symantec / security.com — Warlock ransomware attackers hit water and telecom operators (1 Oct 2026) · Vendor: Broadcom Symantec Threat Intelligence — Warlock / Longlegs (Storm-2603) · CVE: CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, CVE-2026-58644, CVE-2026-50522, CVE-2026-55040 · SecurityWeek — Warlock expands SharePoint exploitation in critical infrastructure attacks (2 Oct 2026)

breaches network ot ics