← All news
RansomwareThreat IntelligenceIncident Response

A Chinese Ransomware Group Is Still Breaking In Through SharePoint, and This Time It Hit a Water Utility and a Telecom Provider

Obiguard Research Team·October 6, 2026·4 min read

The Warlock ransomware group is still getting into organisations through Microsoft SharePoint, more than a year after the "ToolShell" flaws were first exploited. Symantec's Threat Hunter Team reported on 2 October that the China-based operator has hit at least four organisations in Portuguese- and Spanish-speaking countries over the past two months, according to SecurityWeek and The Record.

Who was hit

The victims span Europe, Africa and Latin America:

  • A water utility
  • A telecommunications provider
  • A regional government body
  • A university

Symantec tracks the operator as Longlegs, also known as Storm-2603. It says the focus on Portuguese- and Spanish-speaking countries could reflect opportunistic targeting of exposed, vulnerable SharePoint servers, or a more deliberate tasking.

How the attack worked

The entry point was SharePoint. The group exploited the ToolShell vulnerabilities from 2025 along with several newer SharePoint flaws, including CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, CVE-2026-58644, CVE-2026-50522 and CVE-2026-55040, per SecurityWeek. Once inside, the reported steps were:

  1. Reconnaissance using tools chosen to look like ordinary developer and administrator traffic.
  2. Persistence through Visual Studio Code's tunnel feature. In one case the attackers installed code-insiders.exe as a service to get covert remote access.
  3. Disabling defences. A tool that turns off security software was run on more than 40 systems, using DLL sideloading and a vulnerable driver.
  4. Delivery of payloads through legitimate file-sharing and storage services.
  5. Domain-wide encryption, staging the ransomware on the SYSVOL share so it could run across many hosts.

Symantec's summary is blunt: ToolShell and related SharePoint flaws remain a viable initial access route. The advice is to patch every SharePoint deployment or apply the vendor mitigations.

Why this one matters

Nothing in this campaign is new. That is the point. An internet-facing collaboration server with known flaws is still enough to reach a water utility's network, and the tools used afterwards (a VS Code tunnel, a signed driver, a file share) are all legitimate software doing unexpected things.

Defenders should take three things from it:

  • Inventory exposed SharePoint servers, including old ones nobody remembers owning, and confirm each is patched.
  • Treat developer tooling as an attack surface. A VS Code tunnel service on a server that has no developers using it is a strong signal.
  • Alert on defences going quiet. Security software disabled across dozens of hosts is detectable if someone is watching the telemetry.

Where a SOC fits

The patch is the fix for the entry point. The rest of the chain happens after a successful exploit, and that is where monitoring decides how far an intruder gets. Reconnaissance, a new service installing a tunnel, an agent going silent on 40 machines and a burst of file changes on SYSVOL each leave a trace in endpoint, identity and network logs.

Obiguard SOC is a managed security operations service that watches that telemetry around the clock. Analysts triage alerts, investigate behaviour such as unexpected remote-access services or security tools being stopped, and escalate with the context a small IT team needs to act, before an attacker reaches the point of encrypting a domain. For organisations that run critical services on a lean security team, as water and telecom operators often do, that coverage is the gap the Warlock campaign exploits.

It does not replace patching. If a vulnerable SharePoint server is exposed, it will keep being attacked. A SOC shortens the time between the break-in and someone noticing it.

The question to take away

If an attacker installed a remote-access tunnel on one of your servers tonight, and security agents on 40 hosts stopped reporting, who would see it before morning?

Explore Obiguard SOC or talk to us about 24/7 monitoring for your environment.

How Obiguard helps

Turn this into enforced policy, not just awareness.

Obiguard sits in front of every AI request your organization makes — screening prompts and outputs against the guardrails, compliance frameworks, and audit trails that stories like this one make necessary.

See how it works →