Unpatched SharePoint Is an OT Problem: Lessons from Warlock’s Water and Telecom Hits

Alright, mi gente. Nobody wants to hear that the document library is part of keeping the plant alive.

Mira: it is.

Symantec just walked a campaign where Warlock ransomware, from the crew they call Longlegs (Microsoft tracks them as Storm-2603), hit at least four organizations in Portuguese- and Spanish-speaking countries across Europe, Africa, and Latin America. In that cluster: a water utility, a telecom, a regional government body, and a university. Nobody named the victims. Nobody named the countries.

How they got in, typically: holes in on-premises Microsoft SharePoint. Not the cloud version. The farm still sitting on your network.

In one critical-infrastructure case Symantec dissected, the clock looked like this. SharePoint webshell on July 22, 2026. Recon, machine-key abuse, domain staging. By July 31, Warlock on a pile of hosts. Nine days from “intranet problem” to domain-scale encryption.

Claro. That is IT ransomware hitting a water organization. Nobody published evidence that PLCs got encrypted, treatment settings got flipped, or water quality took a hit. Good. Still your problem. When the domain holding your drawings, SOPs, and SCADA archives goes dark, the crew feels it even if the pumps keep spinning.

This isn’t a brand-new family. It’s a homework reminder.

Warlock showed up around June 2025. CISA was already talking about actors encrypting files and dropping Warlock on compromised SharePoint boxes during the ToolShell wave. October 2026 is continuity.

Symantec calls Longlegs China-nexus and ties them to Storm-2603 plus some older clusters. Microsoft says moderate confidence they’re China-based, and hasn’t publicly glued them to other named Chinese APTs. Fine. Quote it once, then move on. Your Monday job is not geopolitics. It’s whether that SharePoint node still answers from the internet.

Symantec puts the recent multi-victim window roughly in the two months before their ~October 1 write-up, with the detailed CI timeline starting July 22. Older Warlock geography once included places like the United States. That is history, not a claim that this four-victim cluster includes a US water utility. We work with what was reported.

Nine days that should make your MSP sweat

After they land on SharePoint, the pattern Symantec describes is ugly and practical.

Webshell under LAYOUTS paths. Harvest of ASP.NET machine keys, so forged ViewState-style payloads can keep running even after you patch if you never rotated keys. Sideloading. Follow-on payloads from places that look like normal cloud traffic. Living-off-the-land recon, then NetExec for Active Directory work. Remote access through Visual Studio Code Insiders installed as a tunnel service. Signed Microsoft binary. Traffic that can blend with “the engineer is debugging.”

Before the locker: an AV/EDR killer hit at least 40 hosts in about two hours. Warlock then hit at least 33. They staged under the domain SYSVOL scripts path so ordinary domain replication patterns helped push ransomware around. Quieter than hammering every host one by one. They also added a fake-looking SharePoint setup account (SPSEPRDSetup) to local Administrators on multiple machines.

Symantec still lists the ToolShell-era CVEs as likely tools (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, CVE-2025-53771), plus “newer SharePoint flaws” that CISA flagged in July 2026. They do not tell you which CVE opened each 2026 door. So don’t invent one for the water utility. Just patch what CISA and Microsoft put in front of you, and hunt before you trust the box.

One precision note for the nerds: in other recent Longlegs jobs, Symantec points at the vulnerable signed driver K7RKScan (CVE-2025-1055) for BYOVD EDR kills. In the July 22 CI intrusion, they never named the driver. Leave it there.

Why your SharePoint farm sits on the critical path

Small water and wastewater shops don’t run malware research labs. They run thin IT. Often shared with the city, the county, a regional authority, or an MSP.

That on-prem SharePoint farm? It usually holds the drawings and P&IDs. The SOP PDFs. Contractor packages. SCADA and HMI project archives. Work orders. Sometimes the jump-host docs and VPN runbooks people actually use on Saturday night.

When ransomware lands on the domain that owns that farm, especially via SYSVOL, you don’t just lose the wiki.

You lose ops paperwork, tickets, maps, email. Crews scramble without the tools they need to run a shift. You lose engineering truth if the only clean SCADA configs lived on that domain. If engineering laptops, VPN boxes, or SCADA jump hosts are domain-joined or share credentials the attackers just owned, IT ransomware becomes an OT availability problem without anyone writing a PLC exploit. Same Active Directory, same trust boundary. OT that trusts that AD inherits the pain.

One contrast, then we move: this is not the late-August Colorado story where foreign actors changed OT equipment settings, killed alarms, and messed with pumping cycles on tiny providers. Different movie. Warlock, as reported, is SharePoint to domain ransomware into a water organization. Same Monday question, though. Can you still run the plant when the business network is a mess?

We’ve seen this class before. Maine WWS in 2021 (ZuCaNo): ransomware on a SCADA computer through remote access, back to manual until restore. California WWS (Ghost, 2021): ransom notes on three SCADA servers. Nevada WWS that same year: ransomware hit SCADA visibility and backups. Colonial Pipeline: ransomware on IT forced operational shutdown decisions without a magical pipeline PLC zero-day. Water gets hurt by ransomware on the systems people need to run the plant. Not only by exotic ICS exploits.

Bottom line

For small water and wastewater systems, the SharePoint farm on the business network is part of the control system’s resilience story. Warlock’s recent water and telecom hits show how unpatched collaboration software turns IT ransomware into plant-week chaos, even when nobody touches a PLC.

Basics beat geopolitics. Inventory the exposure. Patch and rotate keys. Watch for EDR mass-death. Keep OT configs and the paperwork recoverable when the domain is not.

Stay sharp out there. Stay safe. And por favor, ask your MSP which SharePoint node still answers from the public internet.

Javier

Sources

  1. https://www.security.com/threat-intelligence/warlock-ransomware-critical-infrastructure
  2. https://www.broadcom.com/support/security-center/protection-bulletin/warlock-ransomware-targets-water-and-telecom-operators
  3. https://www.bleepingcomputer.com/news/security/warlock-ransomware-breach-sharepoint-in-water-telecom-operator-attacks/
  4. https://thehackernews.com/2026/10/warlock-exploits-sharepoint-flaws-to.html
  5. https://www.darkreading.com/cyberattacks-data-breaches/warlock-ransomware-spanish-portuguese
  6. https://www.cisa.gov/news-events/alerts/2025/07/20/update-microsoft-releases-guidance-exploitation-sharepoint-vulnerabilities
  7. https://www.cisa.gov/news-events/alerts/2025/07/20/cisa-adds-one-known-exploited-vulnerability-cve-2025-53770-toolshell-catalog
  8. https://www.cisa.gov/news-events/analysis-reports/ar25-218a
  9. https://www.cisa.gov/news-events/alerts/2025/08/06/cisa-releases-malware-analysis-report-associated-microsoft-sharepoint-vulnerabilities
  10. https://www.microsoft.com/en-us/security/blog/2025/07/22/disrupting-active-exploitation-of-on-premises-sharepoint-vulnerabilities/
  11. https://www.cisa.gov/news-events/alerts/2026/07/14/cisa-urges-sharepoint-hardening-after-new-exploitations
  12. https://www.cisa.gov/news-events/alerts/2024/02/21/cisa-epa-and-fbi-release-top-cyber-actions-securing-water-systems
  13. https://www.cisa.gov/sites/default/files/2024-02/fact-sheet-top-cyber-actions-for-securing-water-systems.pdf
  14. https://www.cisa.gov/sites/default/files/2025-05/fact-sheet-primary-mitigations-to-reduce-cyber-threats-to-operational-technology-508c.pdf
  15. https://www.cisa.gov/news-events/cybersecurity-advisories/aa21-287a
  16. https://www.cisa.gov/stopransomware/ransomware-guide
  17. https://www.cisa.gov/news-events/news/attack-colonial-pipeline-what-weve-learned-what-weve-done-over-past-two-years

Leave a comment