logo

Warlock Ransomware Evolves: New Tools and Kernel-Level Evasion Threaten Global Sectors

ID: 8fe15aa6-42ff-57de-927d-3af15049457e

STIX ID: report--8fe15aa6-42ff-57de-927d-3af15049457e

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-03-19

Date Updated: 2026-04-23

Author: Ddos

...
...

Trend Micro's report details how the Warlock ransomware group has advanced from exploiting unpatched Microsoft SharePoint servers for initial access to employing sophisticated post-exploitation techniques—most notably a Bring Your Own Vulnerable Driver (BYOVD) exploit against NSecKrnl.sys to terminate security products at the kernel level—while using legitimate remote-access tools (TightVNC, VS Code/Cloudflare tunnels), a custom reverse proxy (Yuze), GPO-driven mass deployment, and renamed Rclone for exfiltration to S3; the group demonstrated long dwell times and targeted high-value sectors across multiple countries.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.