Warlock Hit Water and Telecom Operators
On 1 October, Symantec attributed at least four attacks over two months to Longlegs. The unnamed victims included water and telecommunications operators; no publication time was given.
One victim, 22 to 31 July 2026
The detailed chronology covers one victim. Symantec says likely SharePoint exploitation preceded a web shell, machine-key abuse, a Visual Studio Code Insiders tunnel and NetExec. A disabling tool reached at least 40 hosts; Warlock reached at least 33.
Symantec identified neither the exact entry CVE nor the disabling tool’s likely vulnerable driver. SYSVOL replication delivered staged files to three observed hosts. It did not execute them. Symantec assesses a China nexus.
Restore trust, not just software
CISA’s guidance supports patching every farm node, reducing exposure, enabling AMSI Full Mode and hunting before key rotation. Microsoft documents supported, edition-specific machine-key procedures. Follow the procedure for the deployed topology.
BlackTree’s earlier analysis explains why stolen machine keys can outlive a patch. It is recovery context, not proof of this campaign’s entry flaw.
Sources
- Symantec Threat Hunter Team: Warlock Ransomware Attackers Hit Water and Telecom Operators, published 1 October 2026; no public time provided.
- CISA: SharePoint hardening after new exploitations, updated through 26 August 2026.
- Microsoft Learn: ASP.NET view state security and key management, inspected 2 October 2026.


