chiprook
← Security
SecurityOctober 2, 2026, 07:41

Warlock ransomware spread via SYSVOL after SharePoint compromise

Symantec and Carbon Black detailed attacks by the Longlegs (Storm-2603) group against water and telecom operators. After likely exploiting a SharePoint vulnerability, attackers deployed an ASPX webshell, ran AV/EDR killers on 40 machines and dropped the Warlock binary with a ransom note on 33 hosts, distributing it via SYSVOL replication between domain controllers.

Warlock ransomware spread via SYSVOL after SharePoint compromise
#Microsoft#SharePoint#Warlock
Read next
Security

Fake passkey setup requests lead to Microsoft 365 compromises

Security

Warlock Ransomware Hits Major Spanish, Portuguese Organizations

Security

Compromised MemTensor packages push sckit credential stealer via npm and PyPI

Security

Attacker compromised nearly 1,000 Zyxel switches via CVE-2026-7273