{"id":24072,"date":"2025-05-17T07:00:00","date_gmt":"2025-05-17T04:00:00","guid":{"rendered":"https:\/\/forklog.com\/en\/a-printer-with-a-sting-the-dior-breach-and-other-cybersecurity-highlights\/"},"modified":"2025-05-17T07:00:00","modified_gmt":"2025-05-17T04:00:00","slug":"a-printer-with-a-sting-the-dior-breach-and-other-cybersecurity-highlights","status":"publish","type":"post","link":"https:\/\/u1f987.com\/en\/a-printer-with-a-sting-the-dior-breach-and-other-cybersecurity-highlights\/","title":{"rendered":"A printer with a sting, the Dior breach and other cybersecurity highlights"},"content":{"rendered":"<p>We collected the week\u2019s most important cybersecurity news.<\/p>\n<div class=\"wp-block-text-wrappers-keypoints article_keypoints\">\n<ul class=\"wp-block-list\">\n<li>Procolored printer drivers contained a cryptocurrency stealer.<\/li>\n<li>In the US, 12 suspects in $263m crypto fraud were arrested.<\/li>\n<li>Dior confirmed a cyberattack and data leak.<\/li>\n<li>Telegram purged casino bots.<\/li>\n<\/ul>\n<\/div>\n<h2 class=\"wp-block-heading\"><strong>Procolored printer drivers hid a crypto-stealer<\/strong><\/h2>\n<p>For at least six months, official software bundled with Procolored printers included a remote-access trojan and a cryptocurrency stealer. The first to <a href=\"https:\/\/www.hackster.io\/news\/the-maker-s-toolbox-procolored-v11-pro-dto-uv-printer-review-680d491e17e3\">flag<\/a> it was YouTube blogger Serial Hobbyism.<\/p>\n<p>After installing drivers for the Procolored V11 Pro UV printer, a user\u2019s antivirus detected the Floxif USB worm on the computer.<\/p>\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/lh7-qw.googleusercontent.com\/docsz\/AD_4nXeCvJg-ZXV_rkl9iwJ1gIvAqmgxD5KW_j8gCM0L2FwS1TpQaTjN_RK8BPttrMlzql02i9B-V_CIaXoxDvKb8pv5L7g93saWZFa7Zj4OAtlipTT0HwEqzrzVcc3dyn1IYm9nMraPkw?key=Z11iMuYCYbxTivfaSIQU5w\" alt=\"A printer with a sting, the Dior breach and other cybersecurity highlights\"\/><figcaption class=\"wp-element-caption\">Data: Serial Hobbyism.<\/figcaption><\/figure>\n<p>External experts helped the blogger <a href=\"https:\/\/www.gdatasoftware.com\/blog\/2025\/05\/38200-printer-infected-software-downloads\">determine<\/a> that at least six printer models (F8, F13, F13 Pro, V6, V11 Pro and VF13 Pro) with companion software hosted on the Mega file-sharing platform contained the XRedRAT trojan and the SnipVex clipper. The latter infects .exe files and replaces Bitcoin addresses in the clipboard.<\/p>\n<p>The address used by SnipVex to siphon stolen cryptocurrency received about 9.308 BTC (~$1m at the time of the report).<\/p>\n<p>The malicious packages have been removed and an internal investigation has begun.<\/p>\n<h2 class=\"wp-block-heading\"><strong>US arrests 12 over crypto fraud totalling <\/strong><strong>$263m\u00a0<\/strong><\/h2>\n<p>US authorities have <a href=\"https:\/\/www.justice.gov\/usao-dc\/pr\/additional-12-defendants-charged-rico-conspiracy-over-263-million-cryptocurrency-thefts\">charged<\/a> 12 individuals in a cybercriminal conspiracy involving extortion, fraud and money laundering that netted more than $263m.<\/p>\n<p>According to the Department of Justice, from October 2023 to March 2025 the group of American and foreign nationals carried out database breaches, phishing, and home burglaries aimed at stealing hardware crypto wallets.<\/p>\n<p>The proceeds were spent at nightclubs, on private-jet rentals, hired security and sports cars priced up to $3.8m. Some $9m went on exotic cars and another $4m on parties.<\/p>\n<p>Part of the scheme was exposed by on-chain sleuth ZachXBT, who in August 2024 <a href=\"https:\/\/u1f987.com\/en\/news\/us-authorities-arrest-suspects-in-4100-btc-theft-from-genesis-creditor\">tracked the theft<\/a> of nearly 4,100 BTC from an early crypto investor.<\/p>\n<p>The investigation is ongoing.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Dior confirmed a cyberattack and data leak<\/strong><\/h2>\n<p>The French luxury brand Dior <a href=\"http:\/\/dior.com\/ko_kr\/fashion\">said<\/a> it identified on May 7 a cybersecurity incident that resulted in unauthorised access to partial customer information.<\/p>\n<p>Data affected include names, gender, phone numbers, email, addresses, purchase history and preferences. The company assured that the database did not contain account passwords or financial information, including bank details, card data or IBAN.<\/p>\n<p>Steps have been taken to contain the breach, and an investigation is under way with cybersecurity experts. The data-protection authority and affected customers have been notified.<\/p>\n<p>The number of affected customers and their regions have not been disclosed.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Telegram purged casino bots<\/strong><\/h2>\n<p>Messenger Telegram removed the platform\u2019s largest gambling project, @CasinoBot. A broad sweep also hit several other major projects with million-strong audiences, reported <a href=\"https:\/\/t.me\/d_code\/22366\">\u201cDurov\u2019s Code\u201d<\/a>.<\/p>\n<p>Before that, the messenger blocked search for key words such as \u201ccasino\u201d, \u201cfreespin\u201d and \u201c\u043a\u0430\u0437\u0438\u043d\u043e\u201d, depriving such projects of organic traffic.<\/p>\n<p>Telegram is reportedly tightening content moderation amid rumours of a possible IPO, aiming to minimise potential regulatory complaints.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Alleged BlackDB admin extradited to the US from Kosovo<\/strong><\/h2>\n<p>A 33-year-old Kosovo citizen, Liridon Mazurika, has been extradited to the US on charges of running the cybercrime marketplace BlackDB, active since 2018, the Department of Justice <a href=\"https:\/\/www.justice.gov\/usao-mdfl\/pr\/administrator-online-criminal-marketplace-extradited-kosovo-united-states\">reports<\/a>.<\/p>\n<p>According to prosecutors, he was the lead administrator of the platform, which sold compromised accounts, server data, stolen credit-card numbers and personal information on individuals, most of them US citizens.<\/p>\n<p>The first court hearing has already taken place. The defendant was charged with five counts of fraudulent use of unauthorised access devices and one count of conspiracy to commit fraud. He faces up to 55 years in prison.<\/p>\n<p>Meanwhile, in Moldova a 45-year-old \u201cforeign citizen\u201d was <a href=\"https:\/\/politia.md\/ro\/content\/cetatean-strain-aflat-cautare-internationala-pentru-comiterea-infractiunilor-cibernetice\">arrested<\/a> on suspicion of using the DoppelPaymer ransomware.<\/p>\n<p>Authorities believe that in 2021 the suspect was behind a series of cyberattacks on Dutch organisations. One victim was <span data-descr=\"Dutch Research Council\" class=\"old_tooltip\">NWO<\/span>, which suffered losses of around \u20ac4.5m.<\/p>\n<p>Officers seized an e-wallet, \u20ac84,800, two laptops, a mobile phone, a tablet, six bank cards and several storage devices. He remains in custody pending extradition to the Netherlands.<\/p>\n<h2 class=\"wp-block-heading\"><strong>A third of Russian courts\u2019 archive disappeared after a cyberattack<\/strong><\/h2>\n<p>Some 33% of the case archive (89m records) were deleted from the \u201cconsolidated database\u201d of the <span data-descr=\"state automated system\" class=\"old_tooltip\">\u0413\u0410\u0421<\/span> \u201cPravosudie\u201d system after a mass outage in October 2024, according to a <a href=\"https:\/\/t.me\/expertgd\/12660\">report<\/a> by Russia\u2019s Audit Chamber.<\/p>\n<p>The Telegram channel <a href=\"https:\/\/t.me\/tochno_st\/518\">\u201cIf We\u2019re Precise\u201d<\/a> explains that the missing cases should remain on the websites of district and magistrates\u2019 courts, but \u201cyou won\u2019t be able to collect them without special tools\u201d.<\/p>\n<p>According to the report, the last external security assessment of the \u0413\u0410\u0421 \u201cPravosudie\u201d websites was conducted in 2015; the system has never been fully updated and runs on \u201ctechnically outdated foreign software products\u201d.<\/p>\n<p>The courts\u2019 websites came back online only a month after the cyber incident. The Ukrainian group BO Team claimed responsibility.<\/p>\n<p>Also on ForkLog:<\/p>\n<ul class=\"wp-block-list\">\n<li>The former head of the DeGods project <a href=\"https:\/\/u1f987.com\/en\/news\/former-degods-ceo-loses-16-nfts-worth-19000-in-hack\">lost 16 NFTs to theft<\/a> worth $19,000.<\/li>\n<li>Analysts outlined the <a href=\"https:\/\/u1f987.com\/en\/news\/analysts-outline-timing-of-stolen-cryptocurrency-movements\">timing of movements<\/a> of stolen cryptocurrencies.<\/li>\n<li>AMLBot found a <a href=\"https:\/\/u1f987.com\/en\/news\/amlbot-exposes-vulnerability-in-tethers-wallet-freezing-system\">vulnerability in the blocking system<\/a> of Tether wallets.<\/li>\n<li>Coinbase <a href=\"https:\/\/u1f987.com\/en\/news\/coinbase-discloses-data-breach-and-declines-20-million-ransom\">disclosed a data theft<\/a> and refused to pay a $20m ransom.<\/li>\n<li>The scam marketplace <a href=\"https:\/\/u1f987.com\/en\/news\/fraudulent-marketplace-haowang-shuts-down-following-telegram-channel-blockade\">Haowang shut down<\/a> after its Telegram channels were blocked.<\/li>\n<li>Curve Finance <a href=\"https:\/\/u1f987.com\/en\/news\/curve-finance-confirms-dns-server-compromise\">confirmed a compromise<\/a> of its DNS server.<\/li>\n<li>Charles Hoskinson announced a <a href=\"https:\/\/u1f987.com\/en\/news\/charles-hoskinson-announces-private-stablecoin-on-cardano\">privacy-focused stablecoin<\/a> on Cardano.<\/li>\n<li>Ledger regained <a href=\"https:\/\/u1f987.com\/en\/news\/ledger-regains-control-of-discord-channel-following-hacker-attack\">control of its Discord channel<\/a> after a hack.<\/li>\n<li>An expert suggested the emergence of <a href=\"https:\/\/u1f987.com\/en\/news\/expert-predicts-rise-of-dark-stablecoins\">\u201cdark stablecoins\u201d<\/a>.<\/li>\n<li>In Las Vegas, teenagers <a href=\"https:\/\/u1f987.com\/en\/news\/teenagers-in-las-vegas-accused-of-kidnapping-and-robbing-crypto-investor\">kidnapped and robbed<\/a> a crypto investor.<\/li>\n<li>Prosecutors in the Samourai Wallet case <a href=\"https:\/\/u1f987.com\/en\/news\/prosecutors-refuse-to-drop-case-against-samourai-wallet-developers\">refused to drop the case<\/a> despite orders.<\/li>\n<\/ul>\n<h2 class=\"wp-block-heading\"><strong>What to read this weekend?<\/strong><\/h2>\n<p>We unpack DePAI \u2014 a new trend in the machine economy \u2014 and its potential risks.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>We collected the week\u2019s most important cybersecurity news. Procolored printer drivers contained a cryptocurrency stealer. In the US, 12 suspects in $263m crypto fraud were arrested. Dior confirmed a cyberattack and data leak. Telegram purged casino bots. Procolored printer drivers hid a crypto-stealer For at least six months, official software bundled with Procolored printers included [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":24071,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"select":"","news_style_id":"","cryptorium_level":"","_short_excerpt_text":"","creation_source":"","_metatest_mainpost_news_update":false,"footnotes":""},"categories":[3],"tags":[1238,1233],"class_list":["post-24072","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news-and-analysis","tag-cybersecurity-digest","tag-industry-digests"],"aioseo_notices":[],"amp_enabled":true,"views":"13","promo_type":"","layout_type":"","short_excerpt":"","is_update":"","_links":{"self":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts\/24072","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/comments?post=24072"}],"version-history":[{"count":0,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts\/24072\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/media\/24071"}],"wp:attachment":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/media?parent=24072"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/categories?post=24072"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/tags?post=24072"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}