Warlock
Qilin and Warlock Ransomware Use Vulnerable Drivers to Disable 300+ EDR Tools
What happened Threat actors linked to Qilin and Warlock ransomware are using vulnerable signed drivers to disable endpoint security tools on compromised systems. In the Qilin cases, researchers observed a malicious DLL ...
Emulating the Expedited Warlock Ransomware
AttackIQ has released a new attack graph that emulates the behaviors exhibited by Warlock ransomware, which emerged in June 2025. Beginning in July, Warlock operators have primarily targeted internet-exposed, unpatched on-premises Microsoft ...

