Skip to content
feed: live
>_0dayNews
ransomware
● Breaking

Warlock Ransomware Targets Water, Telecom via SharePoint

China-linked Warlock has hit a water utility, telecom provider, regional government, and university via SharePoint exploitation, per Symantec Threat Hunter Team.

Warlock Ransomware Targets Water, Telecom via SharePoint
Photo: 高 长华 / Pexels · Pexels License
airgapMorgan "airgap" Reyes·Published ·1 min read

Warlock has moved into critical infrastructure. The China-linked ransomware group compromised a water utility, a telecom provider, a regional government body, and a university through SharePoint vulnerability exploitation, per a Symantec Threat Hunter Team report published October 2. The SharePoint campaign dates to at least July 2025.

Targets span Portuguese and Spanish-speaking countries. This desk covered Warlock’s earlier campaign against large private-sector organizations in Spain and Portugal yesterday.

Confirmed targets

Water utility, telecom provider, regional government body, and university. Three outlets corroborate the sector list: Symantec, The Record, and BleepingComputer.

Initial access

SharePoint vulnerability exploitation. Specific CVE IDs for the flaws exploited are not confirmed in available reporting. BleepingComputer characterizes the vector as “a variety of vulnerabilities impacting Microsoft SharePoint.” Microsoft’s Security Update Guide is the current reference for outstanding SharePoint advisories.

Sector context

Yesterday’s Warlock coverage focused on large private organizations. Today’s Symantec reporting adds critical infrastructure operators to the confirmed list. Warlock has been active in this region for roughly a year. Symantec characterized the group’s operational profile as more consistent with a state-associated APT than conventional ransomware crews, a pattern this desk noted in yesterday’s article.

Analysis: the addition of water infrastructure and telecom as confirmed targets, combined with the July 2025 campaign start date and geographic focus, fits profiles associated with state-linked collection objectives more than short-term financial extortion. Attribution as China-linked: primary source is Symantec, not independently corroborated at time of publication.

What to watch

Organizations running SharePoint in critical infrastructure sectors should confirm current patch levels against the Microsoft Security Update Guide and review SharePoint access logs for anomalous authentication activity from external addresses. Ransomware operators have targeted critical infrastructure OT networks in recent months through adjacent IT systems.

No IOCs or TTPs have been published outside Symantec’s proprietary report at this time. This story is developing.

Found this useful? Share it.