# Warlock

Published articles for Warlock.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Warlock ransomware breach SharePoint in water, telecom operator attacks

DevFeed: [Warlock ransomware breach SharePoint in water, telecom operator attacks](<https://devfeed.tech/articles/warlock-ransomware-breach-sharepoint-in-water-telecom-operator-attacks-64247.md>)

Original publisher: [Read original article](<https://www.bleepingcomputer.com/news/security/warlock-ransomware-breach-sharepoint-in-water-telecom-operator-attacks/>)

Author: Ionut Ilascu

Published: 2026-10-02T18:33:01Z

Content type: news

Language: en

Sources: [BleepingComputer](<https://devfeed.tech/sources/bleepingcomputer.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [ransomware](<https://devfeed.tech/topics/ransomware.md>), [SharePoint development](<https://devfeed.tech/topics/sharepoint-development.md>)

Tags: [byovd](<https://devfeed.tech/tags/byovd.md>), [china](<https://devfeed.tech/tags/china.md>), [computer-help](<https://devfeed.tech/tags/computer-help.md>), [computer-security](<https://devfeed.tech/tags/computer-security.md>), [computers](<https://devfeed.tech/tags/computers.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [dll-side-loading](<https://devfeed.tech/tags/dll-side-loading.md>), [edr-killer](<https://devfeed.tech/tags/edr-killer.md>), [hacking](<https://devfeed.tech/tags/hacking.md>), [infosec](<https://devfeed.tech/tags/infosec.md>), [infosec-computer-security](<https://devfeed.tech/tags/infosec-computer-security.md>), [initial-access](<https://devfeed.tech/tags/initial-access.md>), [linux](<https://devfeed.tech/tags/linux.md>), [mac](<https://devfeed.tech/tags/mac.md>), [malware](<https://devfeed.tech/tags/malware.md>), [malware-removal](<https://devfeed.tech/tags/malware-removal.md>), [microsoft-sharepoint](<https://devfeed.tech/tags/microsoft-sharepoint.md>), [penetration-testing](<https://devfeed.tech/tags/penetration-testing.md>), [ransomware](<https://devfeed.tech/tags/ransomware.md>), [security](<https://devfeed.tech/tags/security.md>), [sharepoint](<https://devfeed.tech/tags/sharepoint.md>), [spyware](<https://devfeed.tech/tags/spyware.md>), [support](<https://devfeed.tech/tags/support.md>), [tech-support](<https://devfeed.tech/tags/tech-support.md>), [technical-support](<https://devfeed.tech/tags/technical-support.md>), [virus](<https://devfeed.tech/tags/virus.md>), [virus-removal](<https://devfeed.tech/tags/virus-removal.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [warlock](<https://devfeed.tech/tags/warlock.md>), [warlock-ransomware](<https://devfeed.tech/tags/warlock-ransomware.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

Warlock ransomware operators exploited on-premises SharePoint vulnerabilities to breach organizations including a water utility, a telecom provider, a regional government body, and a university. Researchers describe disabling endpoint protection across at least 40 hosts, then deploying ransomware on at least 33, using BYOVD, SYSVOL distribution, VS Code tunneling, and NetExec during the intrusion.

### Source excerpt

The China-linked ransomware group Warlock targeted a water utility, a telecom provider, a regional government body, and a university by exploiting SharePoint vulnerabilities to gain initial access. [...]

## Warlock Expands SharePoint Exploitation in Critical Infrastructure Attacks

DevFeed: [Warlock Expands SharePoint Exploitation in Critical Infrastructure Attacks](<https://devfeed.tech/articles/warlock-expands-sharepoint-exploitation-in-critical-infrastructure-attacks-63891.md>)

Original publisher: [Read original article](<https://www.securityweek.com/warlock-expands-sharepoint-exploitation-in-critical-infrastructure-attacks/>)

Author: Ionut Arghire

Published: 2026-10-02T09:34:41Z

Content type: news

Language: en

Sources: [SecurityWeek](<https://devfeed.tech/sources/securityweek.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [SharePoint development](<https://devfeed.tech/topics/sharepoint-development.md>), [IoT botnets](<https://devfeed.tech/topics/iot-botnets.md>), [national security](<https://devfeed.tech/topics/national-security.md>)

Tags: [asp-net](<https://devfeed.tech/tags/asp-net.md>), [china](<https://devfeed.tech/tags/china.md>), [critical-infrastructure](<https://devfeed.tech/tags/critical-infrastructure.md>), [cve-2026-56164](<https://devfeed.tech/tags/cve-2026-56164.md>), [dll-sideloading](<https://devfeed.tech/tags/dll-sideloading.md>), [exploitation](<https://devfeed.tech/tags/exploitation.md>), [exploited](<https://devfeed.tech/tags/exploited.md>), [hacking](<https://devfeed.tech/tags/hacking.md>), [initial-access](<https://devfeed.tech/tags/initial-access.md>), [malware](<https://devfeed.tech/tags/malware.md>), [malware-threats](<https://devfeed.tech/tags/malware-threats.md>), [ransomware](<https://devfeed.tech/tags/ransomware.md>), [sharepoint](<https://devfeed.tech/tags/sharepoint.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [warlock](<https://devfeed.tech/tags/warlock.md>)

### AI overview

A China-based group tracked as Longlegs and Storm-2603 continues exploiting SharePoint vulnerabilities in attacks attributed to the Warlock ransomware operation. Symantec reports that recent victims included critical infrastructure operators, a regional government body, and a university. The intrusions involved disabling security tools, deploying ransomware, and using Visual Studio Code tunnels for covert access.

### Source excerpt

The China-based hacking group has been exploiting SharePoint vulnerabilities since July 2025. The post Warlock Expands SharePoint Exploitation in Critical Infrastructure Attacks appeared first on SecurityWeek.