Warlock ransomware launched on at least 33 hosts
Malware Activity
Summary
Hide ▲
Show ▼
Warlock ransomware was launched on at least 33 hosts after protection was disabled, compressing the final stage of the intrusion into a rapid network-wide rollout. The deployment followed an AV/EDR-killing tool that turned off defenses on compromised machines. The payload was staged in SYSVOL, enabling broad execution across the environment.
Related Happenings
Warlock SharePoint multi-sector ransomware campaign
Campaign
H score29
First: 02.10.2026 21:33
Last: 02.10.2026 21:33
Sources 1
How related:
The China-linked ransomware group Warlock targeted a water utility, a telecom provider, a regional government body, and a university by exploiting SharePoint vulnerabilities to gain initial access.
About this happening:
The Warlock ransomware campaign is using SharePoint vulnerabilities to break into a water utility, telecom provider, regional government body, and university...
Warlock SharePoint multi-sector ransomware campaign
CampaignHow related: The China-linked ransomware group Warlock targeted a water utility, a telecom provider, a regional government body, and a university by exploiting SharePoint vulnerabilities to gain initial access.
About this happening: The Warlock ransomware campaign is using SharePoint vulnerabilities to break into a water utility, telecom provider, regional government body, and university...
GodDamn ransomware PoisonX BYOVD activity
Malware Activity
H score14
First: 09.07.2026 13:43
Last: 09.07.2026 13:43
Sources 1
About this happening:
GodDamn ransomware, part of the Hyadina family, has evolved into a Windows intrusion chain that uses AnyDesk, credential theft, and the PoisonX kernel driver t...
GodDamn ransomware PoisonX BYOVD activity
Malware ActivityAbout this happening: GodDamn ransomware, part of the Hyadina family, has evolved into a Windows intrusion chain that uses AnyDesk, credential theft, and the PoisonX kernel driver t...
ModeloRAT DNS-delivered malware staging
Malware Activity
H score22
First: 16.02.2026 02:29
Last: 16.02.2026 02:29
Sources 1
About this happening:
ModeloRAT is now being delivered through a DNS-based staging chain, increasing the chance that malicious traffic blends into ordinary name-resolution activity. In the obse...
ModeloRAT DNS-delivered malware staging
Malware ActivityAbout this happening: ModeloRAT is now being delivered through a DNS-based staging chain, increasing the chance that malicious traffic blends into ordinary name-resolution activity. In the obse...
Reynolds ransomware BYOVD defense-evasion activity
Malware Activity
H score31
First: 10.02.2026 16:36
Last: 10.02.2026 16:36
Sources 1
About this happening:
The Reynolds ransomware family now matters because it bundles a vulnerable NsecSoft NSecKrnl driver inside the payload to disable EDR and terminate security processes...
Reynolds ransomware BYOVD defense-evasion activity
Malware ActivityAbout this happening: The Reynolds ransomware family now matters because it bundles a vulnerable NsecSoft NSecKrnl driver inside the payload to disable EDR and terminate security processes...
Timeline
-
02.10.2026 21:33 1 articles · 1h ago
Warlock gains initial access to targeted organizations through SharePoint vulnerabilities
Exploitation ObservedWarlock targeted a water utility, a telecom provider, a regional government body, and a university by exploiting SharePoint vulnerabilities to gain initial access.
Show sources
- Warlock ransomware breach SharePoint in water, telecom operator attacks — www.bleepingcomputer.com — 02.10.2026 21:33
-
02.10.2026 21:33 1 articles · 1h ago
Warlock disables protection software on at least 40 hosts
Victim Impact UpdateIn the intrusion that started on July 22, the attacker deployed a tool that disabled protection software on at least 40 hosts within about two hours; Symantec and Carbon Black say some attacks used an AV/EDR-killing tool delivered via BYOVD with a signed K7RKScan driver vulnerable to CVE-2025-1055.
Show sources
- Warlock ransomware breach SharePoint in water, telecom operator attacks — www.bleepingcomputer.com — 02.10.2026 21:33
-
02.10.2026 21:33 2 articles · 1h ago
Warlock ransomware is launched on at least 33 hosts
Victim Impact UpdateOn July 31, after the AV/EDR killer had been deployed, Warlock ransomware appeared almost as soon as protection was disabled on each host and was launched on at least 33 hosts.
Show sources
- Warlock ransomware breach SharePoint in water, telecom operator attacks — www.bleepingcomputer.com — 02.10.2026 21:33
- Warlock ransomware breach SharePoint in water, telecom operator attacks — www.bleepingcomputer.com — 02.10.2026 21:33
-
02.10.2026 21:33 1 articles · 1h ago
Symantec links Warlock ransomware to Longlegs and publishes indicators of compromise
Attribution UpdateSymantec identifies the same actor as Longlegs, attributes the development of Warlock ransomware to the group, and includes indicators of compromise for files and infrastructure used in the attacks.
Show sources
- Warlock ransomware breach SharePoint in water, telecom operator attacks — www.bleepingcomputer.com — 02.10.2026 21:33