Warlock Ransomware Evolves: New Tools and Kernel-Level Evasion Threaten Global Sectors
ID: 8fe15aa6-42ff-57de-927d-3af15049457e
STIX ID: report--8fe15aa6-42ff-57de-927d-3af15049457e
Feed Name: securityonline.info
Trend Micro's report details how the Warlock ransomware group has advanced from exploiting unpatched Microsoft SharePoint servers for initial access to employing sophisticated post-exploitation techniques—most notably a Bring Your Own Vulnerable Driver (BYOVD) exploit against NSecKrnl.sys to terminate security products at the kernel level—while using legitimate remote-access tools (TightVNC, VS Code/Cloudflare tunnels), a custom reverse proxy (Yuze), GPO-driven mass deployment, and renamed Rclone for exfiltration to S3; the group demonstrated long dwell times and targeted high-value sectors across multiple countries.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
