[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f5Mn9X_Wm3tWq-brFNDvYUUZcsQ9y5AEZLTOh4HvCdp0":3},{"article":4,"iocs":37,"watch_terms":41},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":10,"url":11,"image_url":12,"published_at":13,"ingested_at":14,"relevance_score":15,"entities":16,"category_id":17,"category":18,"article_tags":21},"55f728a9-5550-4ffc-b54b-e19bfae314e8","Warlock Ransomware Group Augments Post-Exploitation Activities","warlock-ransomware-group-augments-post-exploitation-activities","In a recent attack, the group showcased stealthier cross-network activity, thanks to its use of a new BYOVD technique and other tools.","The Warlock ransomware group has been observed employing a new Bring Your Own Vulnerable Driver (BYOVD) technique alongside other tools to conduct stealthier post-exploitation activities across compromised networks. This advancement demonstrates the group's evolving operational capabilities to evade detection and maintain persistence after initial compromise.",null,"https:\u002F\u002Fwww.darkreading.com\u002Fthreat-intelligence\u002Fwarlock-ransomware-post-exploitation-activities","https:\u002F\u002Feu-images.contentstack.com\u002Fv3\u002Fassets\u002Fblt6d90778a997de1cd\u002Fblt264596230fa2e85d\u002F69b94ecca34bb9e46e896dc0\u002FWarlock_wizard_(1800)_Tithi_Luadthong_alamy.png?width=1280&auto=webp&quality=80&disable=upscale","2026-03-17T15:36:52+00:00","2026-03-17T17:00:18.60689+00:00",8,[],"7d8b5ab8-ea0b-4ced-ae97-ec251b86993a",{"id":17,"icon":10,"name":19,"slug":20},"Ransomware","ransomware",[22,27,32],{"category":23},{"id":24,"icon":10,"name":25,"slug":26},"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5","Malware","malware",{"category":28},{"id":29,"icon":10,"name":30,"slug":31},"c5eccf7c-abbc-4bd3-bbed-e6da5cba8e73","Incident Response","incident-response",{"category":33},{"id":34,"icon":10,"name":35,"slug":36},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[38],{"type":26,"value":39,"context":40},"Warlock","Ransomware group conducting post-exploitation attacks with BYOVD technique",[]]