Web Shells, Tunnels, and Ransomware: Dissecting a Warlock Attack

Reported 16 Mar 2026 by otx · Severity: medium

The Warlock ransomware group has enhanced its attack chain with improved methods for persistence, lateral movement, and evasion. Their updated toolset includes TightVNC, Yuze, and a persistent BYOVD technique exploiting the NSec driver. The group's primary targets were technology