← Back to Feed

Web Shells, Tunnels, and Ransomware: Dissecting a Warlock Attack

March 16, 2026 · Trend Micro · Severity: CRITICAL

The Warlock threat group has enhanced its attack chain with new tactics, including TightVNC remote access, Yuze tunneling tools, and a persistent Bring Your Own Vulnerable Driver (BYOVD) technique exploiting the NSec driver. These additions improve the group's ability to maintain persistence, move laterally, and evade defensive measures.

Key Takeaways

  • Warlock continues to enhance its attack chain with new tactics to improve persistence, lateral movement, and defense.
  • Warlock continues to enhance its attack chain with new tactics to improve persistence, lateral movement, and defense evasion using an expanded toolset: TightVNC Yuze, and a persistent BYOVD technique leveraging the NSec driver.
☕ Buy a Coffee