Skip to content

Category: Beveiligingsnieuws

BitLocker extortion through printers: what changed

Two recent incidents in Latin America show a new extortion pattern: attackers encrypt disks with BitLocker and trigger ransom notes via office printers. The cases also reveal recurring misuse of RDP, MSSQL misconfigurations, and RMM tools.

Focus: OctLurk and SilkLurk backdoors (Central Asia)

In Central Asia, since January 2025, two new backdoors have been observed: OctLurk and SilkLurk. The attackers use customized loaders, heavy obfuscation, and additional functionality via plug-ins and LurkProxy.

SilverFox uses BYOVD and DLL sideloading

A cybercriminal group, Silver Fox, targeted a Japanese organization in the industrial manufacturing sector. With BYOVD and DLL sideloading, ValleyRAT is delivered for long-term remote access.

INC ransomware: SonicWall SMA 1000 vulnerabilities

Resecurity reports that INC ransomware has been claiming victims faster since the beginning of August 2026 via SonicWall SMA 1000. The chain appears to be driven by zero-days that, among other things, abuse MFA seeds and credentials.

Cyberattack on Economic Beneficiaries Register

Liechtenstein reports that a cyberattack accessed the economic beneficiaries register, impacting around 31,000 people. Authorities say they took immediate steps and saw no signs of data tampering.