Warlock Campaign Adds Kernel-Level Defense Suppression
8 Articles
8 Articles
Warlock campaign adds kernel-level defense suppression
Symantec says the Longlegs/Storm-2603 cluster is still exploiting on-prem SharePoint flaws to deploy Warlock ransomware, now pairing webshell access and forged __VIEWSTATE payloads with the vulnerable signed driver K7RKScan...
Warlock: Ransomware Deployment from SYSVOL After SharePoint Compromise
1. Basic Information Original Title: Warlock Ransomware Attackers Hit Water and Telecom Operators Sources: Symantec and Carbon Black Published: October 1, 2026 Updated: None Severity: Critical Severity Basis: Attacks were reported against at least four organizations, including water and telecommunications operators. In the detailed intrusion at a critical infrastructure organization, the execution of an AV/EDR Killer was recorded on at least 40 …
Warlock Ransomware Exploiting SharePoint Flaws to Attack Water and Telecom Operators
A China-nexus threat actor is continuing to exploit Microsoft SharePoint Server vulnerabilities to deploy Warlock ransomware, with recent attacks striking essential-service and public-sector organizations across Portuguese- and Spanish-speaking countries. Symantec tracks the operator as Longlegs, while Microsoft uses Storm-2603; earlier activity has also been linked to CL-CRI-1040, CamoFei, and ChamelGang. During the past two months, the campaig…
Warlock Ransomware Attackers Hit Water and Telecom Operators
China-nexus group behind Warlock is still exploiting SharePoint vulnerabilities, attacking organizations in Portuguese and Spanish-speaking countries, hitting critical infrastructure, government, and education organizations.
Coverage Details
Bias Distribution
- 100% of the sources lean Right
Factuality
To view factuality data please Upgrade to Premium





