Trend Micro researchers dissect an updated Warlock ransomware attack chain observed in early 2026, where operators spent 15 days inside a victim network before deploying ransomware. The group exploited unpatched Microsoft SharePoint servers for initial access, then expanded its post-exploitation toolkit with TightVNC for

17m read timeFrom trendmicro.com
Post cover image
Table of contents
Lateral MovementDefense Evasion (BYOVD)Exfiltration

Sort: