← Back to Feed
Web Shells, Tunnels, and Ransomware: Dissecting a Warlock Attack
March 16, 2026 · Trend Micro · Severity: CRITICAL
The Warlock threat group has enhanced its attack chain with new tactics, including TightVNC remote access, Yuze tunneling tools, and a persistent Bring Your Own Vulnerable Driver (BYOVD) technique exploiting the NSec driver. These additions improve the group's ability to maintain persistence, move laterally, and evade defensive measures.
Key Takeaways
- Warlock attack chain now includes TightVNC, Yuze tunneling, and persistent BYOVD using the NSec driver for defense evasion.
- The group continues to evolve its tactics with improved persistence, lateral movement, and expanded toolset capabilities.
- BYOVD techniques leveraging legitimate drivers pose significant challenges for traditional endpoint detection systems.