A new extortion cocktail: office printers, small ransoms, and BitLocker
Overview
Recent incidents have revealed a new trend in cyber extortion involving BitLocker, where attackers are using remote desktop protocol (RDP), MSSQL, remote monitoring and management (RMM) tools, web shells, and even office printers to hold data hostage. In these cases, the attackers are demanding small ransoms, which can be appealing to smaller organizations that may not have the resources to recover from a larger attack. This shift in tactics underscores the need for businesses to enhance their security measures, especially regarding printer security and remote access protocols. Companies should be vigilant in monitoring their networks for any unauthorized access or unusual activity that could signal an impending attack. As these methods become more common, organizations must be prepared to defend against them to protect their sensitive data.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: BitLocker, RDP, MSSQL, RMM tools, office printers
- Action Required: Implement strong access controls for RDP, regularly update and patch MSSQL and RMM tools, secure web applications, and ensure office printers are not exposed to the internet.
- Timeline: Newly disclosed
Original Article Summary
We cover two recent cases of BitLocker extortion using RDP, MSSQL, RMM tools, web shells, and printers. The story includes TTPs and recommendations.
Impact
BitLocker, RDP, MSSQL, RMM tools, office printers
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Newly disclosed
Remediation
Implement strong access controls for RDP, regularly update and patch MSSQL and RMM tools, secure web applications, and ensure office printers are not exposed to the internet. Regularly back up data and test recovery plans.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.