Warlock Ransomware SharePoint Attacks

Warlock ransomware SharePoint attacks hit a water utility and a telecom provider. Symantec saw an EDR killer on 40 hosts in two hours. Patch and hunt.

Warlock ransomware SharePoint attacks have reached a water utility, a telecom provider, a regional government body and a university, according to Symantec and Carbon Black. The China-linked group still gets in through on-premises SharePoint, switches off endpoint protection on dozens of machines within about two hours, and then launches ransomware from a share that every…

Read More

GodDamn Ransomware PoisonX Driver Kills EDR

GodDamn ransomware PoisonX driver

The GodDamn ransomware PoisonX driver is a Microsoft-signed kernel tool that ransomware operators use to silently kill EDR and antivirus processes before deploying encryption — and because the driver carries a legitimate Microsoft signature, standard driver-trust checks wave it straight through. What Happened Symantec disclosed on July 9, 2026 that a ransomware family called GodDamn…

Read More