Warlock Ransomware Attackers Hit Water and Telecom Operators
Symantec, Thursday, October 1st, 2026
Symantec says the China-nexus group behind Warlock ransomware hit water and telecom operators via SharePoint flaws.
Symantec reports that Longlegs (aka Storm-2603), the China-nexus developer of Warlock ransomware, attacked at least four organizations in the past two months, including a water utility, a telecom provider, a regional government body and a university in Portuguese- and Spanish-speaking countries.
The group still favors SharePoint vulnerabilities for initial access.
It abuses the vulnerable signed K7RKScan driver to disable security software before deploying ransomware and uses Visual Studio Code tunneling for covert remote access.