Warlock ransomware spread via SYSVOL after SharePoint compromise
Symantec and Carbon Black detailed attacks by the Longlegs (Storm-2603) group against water and telecom operators. After likely exploiting a SharePoint vulnerability, attackers deployed an ASPX webshell, ran AV/EDR killers on 40 machines and dropped the Warlock binary with a ransom note on 33 hosts, distributing it via SYSVOL replication between domain controllers.
- At least four organizations hit, including water and telecom operators
- AV/EDR killer executed on 40 machines in about two hours
- Warlock binary and ransom note seen on at least 33 hosts
- Distribution used the SYSVOL scripts directory and DC replication
Read next
Security