Warlock ransomware post-exploitation tooling upgrades
Malware Activity
Summary
Hide ▲
Show ▼
The Warlock ransomware group has upgraded its post-exploitation toolset with BYOVD, TightVNC, and Yuze, making intrusions harder to detect and interrupt. In an observed January intrusion, operators stayed inside a victim network for 15 days before launching ransomware. The group is also using NSecKrnl.sys to terminate security products at the kernel level, while reusing Velociraptor, Cloudflare tunnels, and disguised Rclone for resilient remote access and exfiltration. The activity strengthens persistence, lateral movement, and defense evasion after entry through unpatched Microsoft SharePoint servers.
Related Happenings
CISA Microsoft SharePoint hardening guidance for exploited zero-days
Advisory/Mitigation
H score46
First: 15.07.2026 17:07
Last: 15.07.2026 17:07
Sources 1
About this happening:
CISA’s Microsoft SharePoint servers hardening guidance responds to newly disclosed zero-day vulnerabilities that can be exploited remotely, creating immediate risk for sup...
CISA Microsoft SharePoint hardening guidance for exploited zero-days
Advisory/MitigationAbout this happening: CISA’s Microsoft SharePoint servers hardening guidance responds to newly disclosed zero-day vulnerabilities that can be exploited remotely, creating immediate risk for sup...
Microsoft SharePoint Server actively exploited multi-CVE wave
Exploitation Wave
H score78
First: 15.07.2026 12:44
Last: 15.07.2026 12:44
Sources 1
About this happening:
SharePoint Server exploitation wave remains active across internet-exposed on-premises instances, with CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164 used...
Microsoft SharePoint Server actively exploited multi-CVE wave
Exploitation WaveAbout this happening: SharePoint Server exploitation wave remains active across internet-exposed on-premises instances, with CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164 used...
SharePoint Server unauthenticated privilege escalation flaw actively exploited (CVE-2026-56164)
Vulnerability
H score82
First: 14.07.2026 23:25
Last: 14.07.2026 23:25
Sources 1
About this happening:
CVE-2026-56164 is an actively exploited SharePoint Server vulnerability that lets an unauthenticated attacker escalate privileges over the network. The flaw puts *...
SharePoint Server unauthenticated privilege escalation flaw actively exploited (CVE-2026-56164)
VulnerabilityAbout this happening: CVE-2026-56164 is an actively exploited SharePoint Server vulnerability that lets an unauthenticated attacker escalate privileges over the network. The flaw puts *...
Latest development: 15.07.2026 12:20
Microsoft’s July 14 Patch Tuesday included CVE-2026-56164, an elevation-of-privilege flaw in Microsoft SharePoint Server that required no existing privileges and was described as low complexity. The zero-day was one of two vulnerabilities in the release that had been exploited in the wild, and Microsoft issued updates for affected systems.
Microsoft releases RoguePlanet Defender security update for CVE-2026-50656
Security Patch Release
H score32
First: 17.06.2026 20:36
Last: 17.06.2026 20:36
Sources 1
About this happening:
Microsoft has released a security update for CVE-2026-50656, remediating RoguePlanet in the Microsoft Malware Protection Engine (mpengine.dll). The flaw is a *...
Microsoft releases RoguePlanet Defender security update for CVE-2026-50656
Security Patch ReleaseAbout this happening: Microsoft has released a security update for CVE-2026-50656, remediating RoguePlanet in the Microsoft Malware Protection Engine (mpengine.dll). The flaw is a *...
Latest development: 09.07.2026 11:48
Microsoft released security updates for CVE-2026-50656, remediating the RoguePlanet privilege-escalation flaw in Microsoft Malware Protection Engine (mpengine.dll) with version 1.1.26060.3008 and additional defense-in-depth updates. Microsoft said no customer action is required to install the update.
Major U.S. services company hit by ransomware attack linked to DragonForce
Incident
H score38
First: 16.06.2026 13:18
Last: 16.06.2026 13:18
Sources 1
About this happening:
A DragonForce ransomware incident hit a major U.S. services firm in December 2025, with attackers maintaining access for one to two months and hiding command-and...
Major U.S. services company hit by ransomware attack linked to DragonForce
IncidentAbout this happening: A DragonForce ransomware incident hit a major U.S. services firm in December 2025, with attackers maintaining access for one to two months and hiding command-and...
Timeline
-
17.03.2026 17:36 2 articles · 4mo ago
Warlock expands SharePoint post-exploitation tooling
Technical Analysis UpdateWarlock, also tracked as Water Manaul, continued exploiting unpatched Microsoft SharePoint servers and expanded its post-compromise toolkit with BYOVD abuse of the NSecKrnl.sys driver, TightVNC, Yuze, Velociraptor, a Cloudflare tunnel, and Rclone disguised as TrendSecurity.exe. An early January intrusion began at the SharePoint worker process (w3wp.exe) on a compromised server, and the operators remained inside the victim network for 15 days before executing ransomware.
Show sources
- Warlock Ransomware Group Augments Post-Exploitation Activities — www.darkreading.com — 17.03.2026 17:36
- Warlock Ransomware Group Augments Post-Exploitation Activities — www.darkreading.com — 17.03.2026 17:36