Skip to content

Category: Software Supply Chain Security

BitLocker extortion through printers: what changed

Two recent incidents in Latin America show a new extortion pattern: attackers encrypt disks with BitLocker and trigger ransom notes via office printers. The cases also reveal recurring misuse of RDP, MSSQL misconfigurations, and RMM tools.

Focus: OctLurk and SilkLurk backdoors (Central Asia)

In Central Asia, since January 2025, two new backdoors have been observed: OctLurk and SilkLurk. The attackers use customized loaders, heavy obfuscation, and additional functionality via plug-ins and LurkProxy.

SilverFox uses BYOVD and DLL sideloading

A cybercriminal group, Silver Fox, targeted a Japanese organization in the industrial manufacturing sector. With BYOVD and DLL sideloading, ValleyRAT is delivered for long-term remote access.

Google Password Manager: malware bypasses passkeys

Unit 42 investigated how malware on a Windows PC can abuse passkey-protected accounts via Google Password Manager in Chrome. The attack is post-compromise: it only starts once the device has already been taken over.

INC ransomware: SonicWall SMA 1000 vulnerabilities

Resecurity reports that INC ransomware has been claiming victims faster since the beginning of August 2026 via SonicWall SMA 1000. The chain appears to be driven by zero-days that, among other things, abuse MFA seeds and credentials.