Skip to content
Warlock ransomware targets water and telecom operators

Warlock ransomware targets water and telecom operators

Broadcom • October 1, 2026

The China-nexus group behind Warlock ransomware is still breaking into organizations through Microsoft SharePoint vulnerabilities, a tactic that brought it to prominence a year ago. In the past two months, the group, which Symantec tracks as Longlegs (aka Storm-2603), attacked at least four organizations in Portuguese- and Spanish-speaking countries across Europe, Africa, and Latin America. The victims included two critical infrastructure operators, a water utility and a telecommunications provider, along with a regional government body and a university.

Symantec protects you from this threat, identified by the following:

SONAR.RansomPlay!gen1

SONAR.SuspLaunch!g193

Associated malicious indicators are blocked and detected by existing policies within Carbon Black products. The recommended policy at a minimum is to block all types of malware from executing (Known, Suspect, and PUP) as well as delay execution for cloud scan to get maximum benefit from Carbon Black Cloud reputation service.

Machine Learning-based

Attack: Ransom.Gen Activity 29

Attack: Ransom.Gen Activity 47

Observed domains/IPs are covered under security categories in all WebPulse enabled products.

Extracted Entities

APT Groups (2)

Attack Types (1)

Platforms (1)

Ransomware Groups (1)