Warlock Ransomware Group Augments Post-Exploitation Activities
ID: ee982154-a25e-580e-b9f7-177132021a94
STIX ID: report--ee982154-a25e-580e-b9f7-177132021a94
Feed Name: Dark Reading
Trend Micro observed the Warlock ransomware group exploiting unpatched Microsoft SharePoint servers to gain access, then using advanced post-exploitation techniques — including BYOVD kernel driver abuse (NSecKrnl.sys), persistent TightVNC services, the Yuze reverse proxy, Velociraptor/Cloudflare tunnels for C2, and Rclone for exfiltration — to improve persistence, lateral movement, and evasion across technology, manufacturing, and government victims in multiple countries. Researchers noted rapid evolution of the group's toolset and recommended immediate patching of public-facing services, removing direct administrative exposure, enforcing MFA, and monitoring for anomalous driver/kernel activity and proxy-based C2.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
