Warlock Attacks Continue Through On-Premises SharePoint, Symantec Reports

Symantec has observed the continued deployment of Warlock ransomware through vulnerable on-premises Microsoft SharePoint servers. At least four victims include a water utility and a telecommunications provider.

Warlock through SharePoint continues even after patches were released: on October 1, 2026, Symantec researchers said that an actor identified as Longlegs was exploiting vulnerabilities in on-premises Microsoft SharePoint Server installations to deploy Warlock ransomware. According to the company, the campaign has affected at least four organizations in Portuguese- and Spanish-speaking countries over the past two months.

The victims reportedly include a water utility, a telecommunications provider, a regional government authority, and a university. Symantec did not disclose their names or the extent of any service outages.

Warlock through SharePoint also hit critical infrastructure

In one documented incident involving critical infrastructure, attackers deployed a tool designed to disable security software on at least 40 systems. They subsequently launched Warlock ransomware on at least 33 systems, Symantec said.

This approach could make it easier for attackers to spread encryption malware throughout the compromised environment. However, based on the available information, the impact of the individual incidents on the operations of the affected organizations is not known.

An older issue involving patches and mitigations

Microsoft confirmed in July 2025 that an actor tracked as Storm-2603 had exploited on-premises SharePoint flaws to deploy Warlock. At the time, the company released updates and mitigation procedures for supported on-premises versions of SharePoint Server.

Symantec links Longlegs specifically to Storm-2603. However, this is an assessment by security researchers; the attribution of the actor and its alleged connection to China are not publicly confirmed attribution to a state entity.

The latest findings also do not specify which particular CVE vulnerabilities were exploited in each of the new incidents. Symantec acknowledges that the attackers may also have had access to newer SharePoint flaws, but this circumstance has not yet been independently confirmed.

Who is at risk

The risk primarily affects unpatched, internet-accessible on-premises SharePoint Server installations. The historical wave referred to as ToolShell involved on-premises servers; according to Microsoft, SharePoint Online in Microsoft 365 was not affected by these flaws.

During the earlier active exploitation, Microsoft recommended not only deploying available updates but also carrying out the appropriate post-compromise steps, including rotating the ASP.NET MachineKey and restarting IIS. Organizations operating on-premises SharePoint should therefore verify their patch status and whether these mitigations have been implemented.

Further developments will show whether Symantec or the affected organizations disclose details about the victims and operational consequences. Confirmation of the specific newer CVEs used in the campaign, as well as further warnings from Microsoft or the U.S. agency CISA regarding active exploitation of SharePoint Server, will also be important.

Sources

  • Symantec Threat Intelligence / SECURITY.COM – The primary report describes new observations of Longlegs/Warlock attacks, at least four victims, and ransomware deployment in critical infrastructure environments.
  • Microsoft Threat Intelligence – In 2025, Microsoft confirmed SharePoint exploitation by Storm-2603 to deploy Warlock and listed available updates and mitigations.
  • SecurityWeek – Independently summarizes Symantec’s recent report and the context of continued SharePoint exploitation.

Verified and updated: 10/02/2026 15:27

Sharing