Warlock Ransomware Exploiting SharePoint Flaws to Attack Water and Telecom Operators (opens in a new tab)
Why readDetails active exploitation of SharePoint ToolShell flaws by China-nexus actor Storm-2603 to deploy Warlock ransomware against critical infrastructure.
Symantec and Microsoft report that China-linked threat actor Storm-2603 (Longlegs) is actively exploiting Microsoft SharePoint vulnerabilities to drop Warlock ransomware. Recent targets include water utilities, telecom providers, and government bodies across Europe, Africa, and Latin America. The campaign leverages the ToolShell exploit chain including CVE-2025-49704 and CVE-2025-49706.
Indicators13
- Hashes
116ca4e88a1bcebb6c0da7fb431c8eca7b8ef3f9767194820c56091972ccac2c155fb1cbdaea12c83ba92d18c88cf38bbc42bb684f913ca0bc26fcf115426a551edb2c0b537cd95bbd5fc16321b4c38a6adf325ccc7b588ad6acc980b0463b60206f27ae820783b7755bca89f83a0fe096dbb510018dd65b63fc80bd20c0326127b7591cf9e1283010ca98fa5dbe970a73fee0d8cde277639924c144718db7c037f94fe1b4a106f02b6f74a69cbc05e69c17406f688beef4c9a045ffcbd2e65e6d07f1232dc59b84038fd0b2e75fdd3d5b825882bb0dba9e6724b7b0823fa3ad73c5268256c9da5488cd9e2b79013060ac321c7e54129344dc7b51e268af36ea8b58f7811a2a2f2a5024220490473774f02759dd2dd904b5b9fabfbaae37125f8ce8d8270ee9de02644530b8dd7fa78973b4a3b80f121e2c5f45ae68cce196f99ceb01f8bf7d6dba2ae07f5bd6070de3ec67b5eb01f969b0ba85e74564fb83a7aaff04d84ef85353966aa4af186ff1254b72c068f33f802417b29dc23fb9f192- Domains
xn8xyt-drop[.]s3[.]wasabisys[.]com