logo

Web Shells, Tunnels, and Ransomware: Dissecting a Warlock Attack

ID: 073fc5d1-2c89-5a53-8b5a-9f867769ce7e

STIX ID: report--073fc5d1-2c89-5a53-8b5a-9f867769ce7e

Feed Name: TrendAI Security Blog

Threat Score
85/100

Date Published: 2026-01-01

Date Updated: 2026-08-27

...
...

This TrendAI report documents an active Warlock (aka Water Manaul) ransomware campaign that exploited unpatched Microsoft SharePoint servers for initial access, spent days performing credential theft and lateral movement (including DCSync and PsExec/PSRemoting), expanded its toolkit to add persistent remote access (TightVNC), multiple covert C2 channels (Velociraptor, Cloudflare Tunnel, VS Code tunnels, Yuze), and a BYOVD kernel-level technique abusing the NSecKrnl.sys driver to disable security products and deploy ransomware across the domain via GPO; the report includes IoCs, indicators, and layered mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.