Find notable cyber news and cases, enriched with sources, timelines, and signals.

Warlock ransomware launched on at least 33 hosts

Malware Activity
First reported
Last updated
Happening score
H score 25
1 unique sources, 1 articles

Summary

Hide ▲

Warlock ransomware was launched on at least 33 hosts after protection was disabled, compressing the final stage of the intrusion into a rapid network-wide rollout. The deployment followed an AV/EDR-killing tool that turned off defenses on compromised machines. The payload was staged in SYSVOL, enabling broad execution across the environment.

Related Happenings

Warlock SharePoint multi-sector ransomware campaign

Campaign
H score29 First: 02.10.2026 21:33 Last: 02.10.2026 21:33 Sources 1

How related: The China-linked ransomware group Warlock targeted a water utility, a telecom provider, a regional government body, and a university by exploiting SharePoint vulnerabilities to gain initial access.

About this happening: The Warlock ransomware campaign is using SharePoint vulnerabilities to break into a water utility, telecom provider, regional government body, and university...

GodDamn ransomware PoisonX BYOVD activity

Malware Activity
H score14 First: 09.07.2026 13:43 Last: 09.07.2026 13:43 Sources 1

About this happening: GodDamn ransomware, part of the Hyadina family, has evolved into a Windows intrusion chain that uses AnyDesk, credential theft, and the PoisonX kernel driver t...

ModeloRAT DNS-delivered malware staging

Malware Activity
H score22 First: 16.02.2026 02:29 Last: 16.02.2026 02:29 Sources 1

About this happening: ModeloRAT is now being delivered through a DNS-based staging chain, increasing the chance that malicious traffic blends into ordinary name-resolution activity. In the obse...

Reynolds ransomware BYOVD defense-evasion activity

Malware Activity
H score31 First: 10.02.2026 16:36 Last: 10.02.2026 16:36 Sources 1

About this happening: The Reynolds ransomware family now matters because it bundles a vulnerable NsecSoft NSecKrnl driver inside the payload to disable EDR and terminate security processes...

Timeline

  1. 02.10.2026 21:33 1 articles · 1h ago

    Warlock gains initial access to targeted organizations through SharePoint vulnerabilities

    Exploitation Observed

    Warlock targeted a water utility, a telecom provider, a regional government body, and a university by exploiting SharePoint vulnerabilities to gain initial access.

    Show sources
  2. 02.10.2026 21:33 1 articles · 1h ago

    Warlock disables protection software on at least 40 hosts

    Victim Impact Update

    In the intrusion that started on July 22, the attacker deployed a tool that disabled protection software on at least 40 hosts within about two hours; Symantec and Carbon Black say some attacks used an AV/EDR-killing tool delivered via BYOVD with a signed K7RKScan driver vulnerable to CVE-2025-1055.

    Show sources
  3. 02.10.2026 21:33 2 articles · 1h ago

    Warlock ransomware is launched on at least 33 hosts

    Victim Impact Update

    On July 31, after the AV/EDR killer had been deployed, Warlock ransomware appeared almost as soon as protection was disabled on each host and was launched on at least 33 hosts.

    Show sources
  4. 02.10.2026 21:33 1 articles · 1h ago

    Symantec links Warlock ransomware to Longlegs and publishes indicators of compromise

    Attribution Update

    Symantec identifies the same actor as Longlegs, attributes the development of Warlock ransomware to the group, and includes indicators of compromise for files and infrastructure used in the attacks.

    Show sources