Warlock: Ransomware Deployment from SYSVOL After SharePoint Compromise
1. Basic Information Original Title: Warlock Ransomware Attackers Hit Water and Telecom Operators Sources: Symantec and Carbon Black Published: October 1, 2026 Updated: None Severity: Critical Severity Basis: Attacks were reported against at least four organizations, including water and telecommunications operators. In the detailed intrusion at a critical infrastructure organization, the…
Warlock ransomware, suspected to be from the Longlegs threat group, was deployed across multiple organizations, including water and telecom operators, after a compromise in their Microsoft SharePoint servers. The attackers gained initial access by exploiting a SharePoint vulnerability and deployed an ASPX webshell. They then used DLL sideloading and remote access tools to gain further access.
The ransomware was placed in the SYSVOL scripts directory, which is replicated across domain controllers via DFS Replication. This allowed the attackers to distribute the ransomware to at least 33 machines, although encryption was not necessarily completed on all of these machines. The attackers used AV/EDR Killers and placed ransom notes on the affected machines.
To prevent such an attack, organizations should ensure their SharePoint servers are up-to-date and secure, restrict external exposure, and monitor for signs of webshell activity. Additionally, application control and vulnerable driver blocklists should be used to prevent execution of unauthorized binaries. Write access to the SYSVOL scripts directory should be restricted, and offline or immutable backups should be verified and tested regularly for Active Directory recovery procedures.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.