Find notable cyber news and cases, enriched with sources, timelines, and signals.

Warlock SharePoint multi-sector ransomware campaign

Campaign
First reported
Last updated
Happening score
H score 29
1 unique sources, 1 articles

Summary

Hide ▲

The Warlock ransomware campaign is using SharePoint vulnerabilities to break into a water utility, telecom provider, regional government body, and university across Europe, Africa, and Latin America. The group emerged in June 2025 and has been active over the past two months, with ToolShell zero-days helping open the door. In a July 22 intrusion, attackers disabled protection on at least 40 hosts and then launched ransomware on at least 33 hosts. Continued exploitation of SharePoint keeps exposed on-premises deployments at risk of follow-on intrusion and extortion.

Related Happenings

Warlock ransomware launched on at least 33 hosts

Malware Activity
H score25 First: 02.10.2026 21:33 Last: 02.10.2026 21:33 Sources 1

How related: The attacker then launched Warlock ransomware on at least 33 hosts.

About this happening: Warlock ransomware was launched on at least 33 hosts after protection was disabled, compressing the final stage of the intrusion into a rapid network-wide rollout. The deploym...

Aurora ransomware Cursor Agent exploitation campaign

Campaign
H score24 First: 28.08.2026 11:00 Last: 28.08.2026 11:00 Sources 1

About this happening: Aurora ransomware operators used Cursor Agent and Claude Sonnet to support post-compromise exploitation against 10 victims between April 8 and May 26, 2026...

Chaos ransomware deployment in STAC4749 intrusions

Malware Activity
H score31 First: 30.07.2026 18:56 Last: 30.07.2026 18:56 Sources 1

About this happening: The Chaos ransomware activity was deployed in at least three intrusions, including one case that reached file encryption in under 17 hours. Attackers used Microsoft...

GodDamn ransomware PoisonX BYOVD activity

Malware Activity
H score14 First: 09.07.2026 13:43 Last: 09.07.2026 13:43 Sources 1

About this happening: GodDamn ransomware, part of the Hyadina family, has evolved into a Windows intrusion chain that uses AnyDesk, credential theft, and the PoisonX kernel driver t...

Medusa ransomware post-compromise deployment

Malware Activity
H score48 First: 07.04.2026 09:35 Last: 07.04.2026 09:35 Sources 1

About this happening: Medusa ransomware activity has broadened from rapid post-compromise deployment into a larger extortion campaign, with CISA, the FBI, and HHS saying it has impacted...

Latest development: 19.08.2026 11:00

CISA, with the FBI and HHS, said Medusa ransomware has impacted more than 500 victims across U.S. critical infrastructure since June 2021, including Healthcare and Public Health, Defense Industrial Base, Critical Manufacturing, Government Services and Facilities, Information Technology, and Financial Services. The advisory said Medusa activity had grown from an estimated over 300 critical infrastructure organizations in March 2025 to more than 500 victims as of April 2026.

Timeline

  1. 02.10.2026 21:33 1 articles · 1h ago

    Warlock disables protection on at least 40 hosts during a SharePoint intrusion

    Exploitation Observed

    Warlock, also tracked as Longlegs, started an intrusion on July 22 after using SharePoint access to gain initial entry, then deployed a tool that disabled protection software on at least 40 hosts within about two hours.

    Show sources
  2. 02.10.2026 21:33 1 articles · 1h ago

    Warlock ransomware appears after protection is disabled on compromised hosts

    Victim Impact Update

    On July 31, Warlock reached the final stage of the intrusion, and ransomware appeared almost as soon as protection was disabled on each host.

    Show sources
  3. 02.10.2026 21:33 2 articles · 1h ago

    Researchers link Warlock to a CVE-2025-1055 BYOVD AV/EDR killer and remote tunneling

    Technical Analysis Update

    Symantec and Carbon Black identified Longlegs as the actor behind Warlock and described an AV/EDR-killing tool delivered with a signed K7RKScan driver vulnerable to CVE-2025-1055; the same analysis also found Visual Studio Code Insiders installed as a service for tunneling and NetExec used for Active Directory enumeration, credential spraying, and remote command execution.

    Show sources