TrendMicro has published an analysis of Warlock, the ransomware group that most likely was behind the attack on Colt.
trendmicro.com/en_us/research/…
@GossiTheDog @campuscodi
#ThreatIntel #Cybersecurity #Infosec
Warlock: From SharePoint Vulnerability Exploit to Enterprise Ransomware
Warlock ransomware exploits unpatched Microsoft SharePoint vulnerabilities to gain access, escalate privileges, steal credentials, move laterally, and deploy ransomware with data exfiltration across enterprise environments.Trend Micro - United States (US)
Christoffer S.
in reply to Christoffer S. • • •Also related:
2025-08-01: research.checkpoint.com/2025/b…
2025-08-04: blog.polyswarm.io/active-explo…
2025-08-06: unit42.paloaltonetworks.com/ak…
Project AK47: Uncovering a Link to the SharePoint Vulnerability Attacks
Hiroaki Hara (Unit 42)