logo

Warlock Ransomware Group Augments Post-Exploitation Activities

ID: ee982154-a25e-580e-b9f7-177132021a94

STIX ID: report--ee982154-a25e-580e-b9f7-177132021a94

Feed Name: Dark Reading

Threat Score
78/100

Date Published: 2026-03-17

Date Updated: 2026-04-21

Author: Elizabeth Montalbano

...
...

Trend Micro observed the Warlock ransomware group exploiting unpatched Microsoft SharePoint servers to gain access, then using advanced post-exploitation techniques — including BYOVD kernel driver abuse (NSecKrnl.sys), persistent TightVNC services, the Yuze reverse proxy, Velociraptor/Cloudflare tunnels for C2, and Rclone for exfiltration — to improve persistence, lateral movement, and evasion across technology, manufacturing, and government victims in multiple countries. Researchers noted rapid evolution of the group's toolset and recommended immediate patching of public-facing services, removing direct administrative exposure, enforcing MFA, and monitoring for anomalous driver/kernel activity and proxy-based C2.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.