← Back to Feed

Web Shells, Tunnels, and Ransomware: Dissecting a Warlock Attack

March 16, 2026 · Trend Micro · Severity: CRITICAL

Warlock continues to enhance its attack chain with new tactics to improve persistence, lateral movement, and defense evasion using an expanded toolset: TightVNC Yuze, and a persistent BYOVD technique leveraging the NSec driver.

Key Takeaways

  • Trend Micro dissected a Warlock attack chain that uses web shells, tunnels, and ransomware with an expanded toolset including TightVNC Yuze.
  • The group employs a persistent bring-your-own-vulnerable-driver technique leveraging the NSec driver for defense evasion during attacks.
  • Defenders should monitor for BYOVD driver abuse and web shell activity, as Warlock continues improving persistence and lateral movement.
☕ Buy a Coffee