Skip to main content
JS
Jacob Santos

Jacob Santos

Threat Hunter, Researcher and Builder

Sr. Threat Researcher | Trend AI
17
Articles
14
Threads
10+
Tools
10+
Talks
Web Shells, Tunnels, and Ransomware: Dissecting a Warlock Attack
Trend Micro Research Mar 2026

Web Shells, Tunnels, and Ransomware: Dissecting a Warlock Attack

RansomwareDefense EvasionAPTBYOVD

Warlock ransomware group (tracked as Water Manaul) exploits unpatched Microsoft SharePoint servers to establish persistent access using BYOVD (Bring Your Own Vulnerable Driver) techniques with the NSec driver to disable endpoint security. New remote access tools like TightVNC and Yuze mask lateral movement across networks. Attackers maintain presence for 15 days before deploying LockBit-derived ransomware. This research documents the complete attack chain from initial compromise through web shell installation, credential dumping, network tunneling, and final ransomware deployment.