Skip to main content
Published Aug 29, 2025 | Updated Apr 16, 2026

Ransom:PowerShell/WarLock.B

Detected by Microsoft Defender Antivirus

Aliases: No associated aliases

Summary

Ransom:PowerShell/WarLock.B is a PowerShell based payload tied to a ransomware-as-a-service (RaaS) operation. Threat actors gain initial access by exploiting unpatched internet facing vulnerabilities, most often in Microsoft SharePoint. After breaking into a network, they spend about 15 days on average doing reconnaissance and stealing data before starting the file encryption phase. The WarLock.B variant handles the final deployment of the ransomware and commonly appends the .x2anylock extension to any file it encrypts.

A notable feature of this threat is its use of the Bring Your Own Vulnerable Driver (BYOVD) technique. By dropping a legitimate but vulnerable driver, the malware deactivates security software at the kernel level before encryption begins. This behavior makes it dangerous because traditional antimalware protection can be rendered useless early in the attack chain. Organizations that run unpatched SharePoint servers or lack driver blocklists face the highest risk from this ransomware.

  • Disconnect compromised servers and workstations from the network to stop the ransomware from spreading laterally through GPO or PsExec.
  • Check for unauthorized changes to the Guest account and any new Group Policy Objects created in the last 14 days.
  • Only restore data from backups that were not connected to the network during the infection, because this ransomware actively deletes local shadow copies and network attached backups.
  • Reset passwords for all domain administrators and service accounts, as the threat actors frequently use credential dumping tools to harvest plaintext passwords from memory.

Microsoft Defender Antivirus automatically removes threats as they are detected. However, many infections can leave remnant files and system changes. Updating your antimalware definitions and running a full scan might help address these remnant artifacts.

You can also visit our advanced troubleshooting page or search the Microsoft virus and malware community for more help.

Follow us