← Back to Feed
Web Shells, Tunnels, and Ransomware: Dissecting a Warlock Attack
March 16, 2026 · Trend Micro · Severity: CRITICAL
Warlock continues to enhance its attack chain with new tactics to improve persistence, lateral movement, and defense evasion using an expanded toolset: TightVNC Yuze, and a persistent BYOVD technique leveraging the NSec driver.
Key Takeaways
- Trend Micro dissected a Warlock attack chain that uses web shells, tunnels, and ransomware with an expanded toolset including TightVNC Yuze.
- The group employs a persistent bring-your-own-vulnerable-driver technique leveraging the NSec driver for defense evasion during attacks.
- Defenders should monitor for BYOVD driver abuse and web shell activity, as Warlock continues improving persistence and lateral movement.