← Back to feed
Breaches & RansomwareEmerging1 sourceOct 4, 2026 · 07:49via Security Affairs

Warlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical Infrastructure

Brief

Warlock ransomware continues to exploit unpatched SharePoint flaws to breach water utilities, telecoms, governments, and universities worldwide.

Warlock ransomware made headlines back in mid-2025 for exploiting a chain of SharePoint zero-days collectively dubbed ToolShell . More than a year later, the same group is still using that door, and it’s still getting in.

Symantec tracks the group behind Warlock as Longlegs, also known as Storm-2603 , and ties it back to older China-nexus clusters called CL-CRI-1040, CamoFei, and ChamelGang. In the past two months alone, Longlegs hit at least four organizations: a water utility, a telecom provider, a regional government body, and a university.

All four sit in Portuguese or Spanish speaking countries, spread across Europe, Africa, and Latin America.

Read more on Security Affairs→