The China-nexus group behind Warlock ransomware is still breaking into organizations through Microsoft SharePoint vulnerabilities, a tactic that brought it to prominence a year ago. In the past two months, the group, which Symantec tracks as Longlegs (aka Storm-2603), attacked at least four organizations in Portuguese- and Spanish-speaking countries across Europe, Africa, and Latin America. The victims included two critical infrastructure operators, a water utility and a telecommunications provider, along with a regional government body and a university.
Symantec protects you from this threat, identified by the following:
SONAR.RansomPlay!gen1
SONAR.SuspLaunch!g193
Associated malicious indicators are blocked and detected by existing policies within Carbon Black products. The recommended policy at a minimum is to block all types of malware from executing (Known, Suspect, and PUP) as well as delay execution for cloud scan to get maximum benefit from Carbon Black Cloud reputation service.
Machine Learning-based
Attack: Ransom.Gen Activity 29
Attack: Ransom.Gen Activity 47
Observed domains/IPs are covered under security categories in all WebPulse enabled products.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
