As cited
Copy frozen at (site build).
ransomware
Web Shells, Tunnels, and Ransomware: Dissecting a Warlock Attack
Warlock has expanded its attack toolkit with TightVNC, Yuze, and a persistent bring-your-own-vulnerable-driver (BYOVD) technique using the NSec driver to strengthen persistence, lateral movement, and defense evasion capabilities. The group continues to refine its attack chain with these additional components.
Why it matters: Organizations facing Warlock threats need visibility into these evolving post-compromise techniques, particularly the persistent BYOVD method, to detect and respond to advanced threat activity targeting their networks.
- Source published
- First seen by Cybersecurity Tracker