BlackTree Security · Infrastructure · Automation · AI

Warlock Hit Water and Telecom Operators

On 1 October, Symantec attributed at least four attacks over two months to Longlegs. The unnamed victims included water and telecommunications operators; no publication time was given.

One victim, 22 to 31 July 2026

The detailed chronology covers one victim. Symantec says likely SharePoint exploitation preceded a web shell, machine-key abuse, a Visual Studio Code Insiders tunnel and NetExec. A disabling tool reached at least 40 hosts; Warlock reached at least 33.

Symantec identified neither the exact entry CVE nor the disabling tool’s likely vulnerable driver. SYSVOL replication delivered staged files to three observed hosts. It did not execute them. Symantec assesses a China nexus.

Restore trust, not just software

CISA’s guidance supports patching every farm node, reducing exposure, enabling AMSI Full Mode and hunting before key rotation. Microsoft documents supported, edition-specific machine-key procedures. Follow the procedure for the deployed topology.

BlackTree’s earlier analysis explains why stolen machine keys can outlive a patch. It is recovery context, not proof of this campaign’s entry flaw.

Sources

Leave a Reply

Your email address will not be published. Required fields are marked *