← Back to Feed

Web Shells, Tunnels, and Ransomware: Dissecting a Warlock Attack

March 16, 2026 · Trend Micro · Severity: CRITICAL

The Warlock threat group has enhanced its attack chain with new tactics, including TightVNC remote access, Yuze tunneling tools, and a persistent Bring Your Own Vulnerable Driver (BYOVD) technique exploiting the NSec driver. These additions improve the group's ability to maintain persistence, move laterally, and evade defensive measures.

Key Takeaways

  • Warlock attack chain now includes TightVNC, Yuze tunneling, and persistent BYOVD using the NSec driver for defense evasion.
  • The group continues to evolve its tactics with improved persistence, lateral movement, and expanded toolset capabilities.
  • BYOVD techniques leveraging legitimate drivers pose significant challenges for traditional endpoint detection systems.
☕ Buy a Coffee