October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix NowOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
World desk3 min

Warlock Ransomware Exploits On-Premises SharePoint in Attacks on Water and Telecom Organizations

Warlock operators exploited vulnerable internet-facing, on-premises SharePoint servers in a reported attack wave that included water and telecom organizations.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Warlock ransomware operators exploited vulnerable internet-facing, on-premises Microsoft SharePoint servers in a reported attack wave that included a water utility and a telecommunications provider.

What happened in the Warlock SharePoint attacks?

Reporting published October 1–2, 2026, describes at least four organizations hit in the current wave: a water utility, a telecommunications provider, a regional government body and a university. Victims were reported in Portuguese- and Spanish-speaking countries across Europe, Africa and Latin America. The reports do not identify the organizations by name, so the sectors and regions are the level of detail that can be confirmed from the available accounts.

Symantec findings summarized by Security.com associate the operation with an actor called Longlegs. Microsoft tracks the China-based ransomware actor involved as Storm-2603. These labels come from different threat-intelligence sources; Microsoft’s statement also distinguishes Storm-2603 from two named Chinese nation-state actors, Linen Typhoon and Violet Typhoon, which it observed exploiting the same SharePoint vulnerabilities. The supplied reporting does not establish that all three names refer to the same group.

How did the attackers breach SharePoint?

Microsoft observed exploitation of four ToolShell vulnerabilities in internet-facing, on-premises SharePoint servers:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • CVE-2025-49704
  • CVE-2025-49706
  • CVE-2025-53770
  • CVE-2025-53771

The reported intrusion chain shows how an exposed server can become a route into a wider organization:

  1. Exploit the public-facing server. The attackers used the SharePoint vulnerabilities to gain an initial foothold.
  2. Install a web shell. They dropped spinstall0.aspx, which could be used to run commands through the SharePoint server’s w3wp.exe process.
  3. Discover systems and steal credentials. Microsoft observed attacker activity including network discovery and credential dumping with Mimikatz.
  4. Move laterally and establish persistence. Reported tools and techniques included PsExec, Impacket and Windows Management Instrumentation (WMI), along with scheduled tasks and IIS persistence.
  5. Weaken defenses and spread the payload. The attackers disabled Microsoft Defender protections and used Group Policy to distribute Warlock ransomware.

BleepingComputer reported that protection was disabled on at least 40 hosts within about two hours, and that at least 33 hosts received Warlock ransomware in the intrusion it described. Microsoft’s updated WarLock.B description says the attackers spent about 15 days on reconnaissance and data theft before encryption. These are figures from different reports and describe different parts of the activity; they should not be treated as a universal timeline for every victim.

Rank #2
Sale
Microsoft® Office SharePoint® Server 2007 Administrator's Companion
  • New
  • Mint Condition
  • Dispatch same day for order received before 12 noon
  • Guaranteed packaging
  • No quibbles returns

Are SharePoint Online sites affected?

Microsoft says this ToolShell guidance applies to on-premises SharePoint Server. SharePoint Online in Microsoft 365 is not affected by these vulnerabilities according to that guidance. Organizations should still determine whether they operate any internet-facing on-premises SharePoint servers, including systems managed by a service provider; the cloud status of one SharePoint environment does not rule out a separate on-premises deployment.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What should an organization do if its SharePoint server is exposed?

If the server may be vulnerable but there is no known compromise

  • Run a supported SharePoint Server version and install Microsoft’s July 2025 security updates for the applicable product.
  • Rotate ASP.NET machine keys and restart IIS, following Microsoft’s ToolShell mitigation guidance.
  • Enable Antimalware Scan Interface (AMSI) in Full Mode.
  • Use Microsoft Defender for Endpoint or equivalent endpoint detection and response controls to monitor the server and connected systems.

If compromise is suspected or confirmed

  • Disconnect compromised systems from the network to contain further activity.
  • Use offline or otherwise unconnected backups for recovery; do not reconnect a backup environment to affected systems before containment and recovery are assessed.
  • Reset domain and service-account passwords, and investigate for unauthorized persistence and lateral movement before restoring normal access.
  • Block known vulnerable drivers with Windows Defender Application Control (WDAC) or an equivalent control.
  • Restrict and log the use of PsExec, PowerShell and Rclone, which Microsoft identifies in its WarLock.B guidance.
  • Engage a qualified ransomware incident response provider if internal teams cannot confidently scope the intrusion, contain it and validate recovery.

Apply these steps with incident responders and Microsoft’s current product guidance: disabling a web shell or reinstalling the server alone does not establish that credentials, other hosts or persistence mechanisms are clear.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #4
Brinero Professional Server Book for Waitress, Dual Core Deluxe Server Book Organizer for a Sturdy Surface, Metal Corners, Server Book - Waitress Book Organizer - Server Books for Waitress
  • 100% Satisfaction Warranty – Our servers book for waitress organization are handcrafted with elegant stitching that lasts. We take pride in offering our customers a waitress book made to exceptional quality standards. To ensure satisfaction, every waiters checkbook is backed by a 1-YEAR WARRANTY. If you are not 100% SATISFIED for any reason we will send you a replacement. No Questions Asked
  • Holds up under Pressure – When you're taking orders the last thing you need is a flimsy waiter book that keeps bending. Our 8”x5” server books for waitress organization is the only one with a premium reinforced dual inner core. Providing an unmatched sturdy reliable writing surface that will last for years
  • On Another Level – Halt the endless cycle of replacing your cheap thin black server book that barely lasts a week. This serving book for waitresses can become your permanent partner. Crafted with overwhelmingly strong attention to detail, the waiter checkbook offers an unparalleled value that you won’t regret investing in
  • Scribble In Style – Impression is everything. You’re making a statement when you bring out this sleek vegan leather serving book. Our serving books have no logos or images and exquisite stitching for a professional feel your colleagues will envy
  • Stay Calm and Collected – Whether you have 1 table or 7, organization is key. This server checkbook has 9 versatile pockets including a durable metal zipper to keep your cash secure. Stay on top of everything with this deluxe server book organizer and bring superior service to every customer

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. Shenzhen desk3 min
    HONOR Expands Beyond Smartphones With Humanoid Robot RevealHONOR said it unveiled its first humanoid robot at MWC 2026 and named shopping assistance, workplace inspections, and supportive companionship as intended uses. Later Robotics D1 claims and a reported…
  2. Cupertino desk5 min
    Apple Unveils AirPods Max 2: The Upgrade That Should Have Happened Years AgoAirPods Max 2 adds H2-powered audio features and Apple claims up to 1.5× more effective ANC, but its design, Smart Case, and 20-hour battery rating are unchanged. Wired lossless audio…
  3. Cupertino desk4 min
    Apple’s OLED Touch MacBooks Are Coming—but the Dynamic Island Is the Real GambleApple has not announced an OLED touchscreen MacBook, but reports point to high-end models arriving in late 2026 or early 2027. The reported Mac Dynamic Island could be useful, but…
Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.