Global Edition
Global Edition
UK Edition
EU Edition
US Edition

Understand the story, not the spin.

Markets

Warlock targeted four organizations through SharePoint

Published 2 October 2026

Symantec researchers reported that the Warlock ransomware group targeted four organizations in Portuguese- and Spanish-speaking countries over two months, including a water utility, a telecommunications provider, a regional government body and a university. In one intrusion involving critical infrastructure, attackers disabled security software on at least 40 hosts within about two hours and deployed Warlock on at least 33 hosts, according to the researchers. The incidents span countries in Europe, Africa and Latin America, but the affected organizations were not identified. Symantec tracks the group as Longlegs; it is also known as Storm2603. Researchers said the group has used vulnerabilities in on-premises Microsoft SharePoint Server to gain initial access. The specific flaws used in these recent intrusions have not been established. In the critical-infrastructure incident, the attackers staged the ransomware in the compromised domain’s SYSVOL share. Ordinary domain replication then distributed the payload across machines, rather than requiring it to be pushed individually to each host, Symantec reported.

Now playing
0:00 / 0:00