Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Trend Micro reported that Warlock attackers in one January 2026 intrusion used TightVNC for persistent remote access, a SOCKS5 proxy for network movement, and a vulnerable driver to interfere with security products. The observed attackers remained inside the victim’s network for 15 days before running ransomware. These are findings from an investigated incident—not proof that every Warlock attack uses the same tools or timeline.
What is Warlock ransomware?
Warlock is the name used in the March 17, 2026, Dark Reading report on Trend Micro’s investigation of ransomware activity. Trend Micro described the group as augmenting its attack chain with methods for persistence, lateral movement, and evasion. Names and attribution can vary across reporting organizations, so the observations below are attributed to the source that reported them.
The report’s central point is that the intrusion did not end with access to a vulnerable server. In the observed case, the attackers used additional remote-access and proxy tools, then attempted to weaken security defenses before executing ransomware.
How did the observed attack unfold?
Initial access: an exposed SharePoint server
Trend Micro reported continued exploitation of unpatched, internet-facing SharePoint servers. In the January intrusion it investigated, the earliest observed process associated with malicious activity was the SharePoint worker process w3wp.exe. This identifies the starting point in that case; it does not establish that all Warlock intrusions begin the same way.
Recommended Free Tools
#1 Best Overall
Persistence and remote access: TightVNC
After access, the attackers reportedly installed TightVNC silently as a Windows service using PsExec. TightVNC provides graphical remote access, while installing it as a service can help maintain access beyond the original compromise. PsExec is a legitimate administration utility, so its presence alone does not prove malicious activity; defenders should examine who ran it, where it ran, and what service or files appeared afterward.
Proxy connections and movement: Yuze
Trend Micro described Yuze as a lightweight, C-based open-source reverse proxy. In the observed activity, it supported SOCKS5 connections over ports 80, 443, and 53. Those commonly used web and DNS ports can make proxy traffic less conspicuous when it blends with expected network activity. The report also places Yuze alongside previously observed Cloudflare tunnels, indicating that the attackers had more than one potential channel for access or movement.
Defense evasion: abuse of a vulnerable driver
The attackers reportedly used a bring-your-own-vulnerable-driver (BYOVD) technique involving NSecKrnl.sys. The driver’s vulnerability was used to terminate security products at kernel level. Dark Reading’s account says this replaced a driver used in earlier campaigns; it does not establish that the same driver will appear in every later incident.
Execution and data movement
In this investigated intrusion, the attackers reportedly spent 15 days inside the victim’s network before executing ransomware. That is a single observed duration, not a group-wide average or typical dwell time. Trend Micro also reported prior use of Rclone disguised as TrendSecurity.exe for data exfiltration. This belongs to the wider set of reported Warlock behaviors, not necessarily to the same sequence or incident as each TightVNC, Yuze, or NSec observation.
Rank #3
What is new about these techniques?
The significance is less that any one tool is unique than that the reported methods serve different purposes and can provide alternatives if one channel is detected or blocked.
| Stage | Reported method | Defensive focus |
|---|---|---|
| Initial access | Exploitation of an unpatched, internet-facing SharePoint server; w3wp.exe was the earliest observed process in the January case. |
Patch exposed SharePoint and other enterprise services; investigate unusual activity from web-server processes. |
| Persistence and remote access | TightVNC installed silently as a Windows service via PsExec. | Review new services, remote-access software, and administrative-tool use in context. |
| Proxying and movement | Yuze SOCKS5 connections over ports 80, 443, and 53; Cloudflare tunnels had also been observed in earlier activity. | Look for unexpected proxy traffic and tunnel use, including connections over common ports. |
| Defense evasion | BYOVD abuse of NSecKrnl.sys to terminate security products at kernel level. |
Investigate unusual driver loading, kernel tampering, and security tools that stop unexpectedly. |
| Exfiltration | Rclone reportedly disguised as TrendSecurity.exe in earlier observed activity. |
Check for unexpected use of file-transfer tools and unusual outbound data movement. |
Microsoft’s WarLock threat description discusses additional techniques, including ToolShell exploitation of SharePoint, ASP.NET MachineKey theft, cloud tunnels, reconnaissance, credential theft, Group Policy abuse, and exfiltration. Those details provide broader context, but they are not the source for the specific TightVNC, Yuze, and NSec observations above and should not be treated as one incident chronology.
Rank #4
How can defenders reduce the risk and spot activity?
Trend Micro’s recommendations focus on reducing exposed entry points and investigating behaviors that may indicate post-compromise activity. No single control is a guarantee against compromise.
- Patch exposed services. Prioritize internet-facing SharePoint and other enterprise services, and track whether fixes are applied to systems reachable from the internet.
- Limit external administrative access. Remove direct internet exposure for RDP and administrative interfaces where possible; restrict access to approved users and paths.
- Require MFA for external entry points. Protect externally accessible services such as VPNs and email with multifactor authentication. A FIDO2 hardware security key is one physical option for implementing MFA; it does not fix a vulnerable SharePoint server.
- Review administration and remote-access activity. Investigate unexpected PsExec use, new services, or remote-access software such as TightVNC, especially when they appear on servers that do not normally need them.
- Look for proxy and tunnel anomalies. Examine unexpected SOCKS or reverse-proxy behavior and unusual connections over ports 80, 443, or 53. Common ports do not make a connection trustworthy.
- Monitor drivers and security-product health. Alert on unusual driver loading, kernel-level interference, or security products that are disabled or terminate unexpectedly.
- Correlate activity across systems. Review lateral movement and outbound data transfers alongside the initial server alert. A web-server process such as
w3wp.exeis more actionable when its activity can be connected to later service creation, proxy traffic, or file movement.
Microsoft’s threat description and Trend Micro’s incident account cover overlapping but not identical observations. For triage, use the specific behaviors as investigative leads rather than treating any single indicator as proof of a Warlock intrusion.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Scan for outdated or missing drivers - takes under a minute3Clear out junk files and repair common Windows errorsQuick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

