Web Shells, Tunnels, and Ransomware: Dissecting a Warlock Attack
ID: 073fc5d1-2c89-5a53-8b5a-9f867769ce7e
STIX ID: report--073fc5d1-2c89-5a53-8b5a-9f867769ce7e
Feed Name: TrendAI Security Blog
This TrendAI report documents an active Warlock (aka Water Manaul) ransomware campaign that exploited unpatched Microsoft SharePoint servers for initial access, spent days performing credential theft and lateral movement (including DCSync and PsExec/PSRemoting), expanded its toolkit to add persistent remote access (TightVNC), multiple covert C2 channels (Velociraptor, Cloudflare Tunnel, VS Code tunnels, Yuze), and a BYOVD kernel-level technique abusing the NSecKrnl.sys driver to disable security products and deploy ransomware across the domain via GPO; the report includes IoCs, indicators, and layered mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
