Technology

Microsoft warns of hackers using BitLocker for ransom attacks

Microsoft has issued an alert about a new threat from a hacker group dubbed DEV-0270, also known as Nemesis Kitten. The group misuses BitLocker to encrypt files on compromised devices.

Ransom attacks

DEV-0270 is said to be a spin-off from an Iranian hacking group also known as Phosphorus. Whoever is behind the new threat, the attackers use various vulnerabilities to infiltrate Windows devices and entire networks and then launch a ransomware attack (via Bleeding computer). So the hackers want to extort ransom money for the release of their victims’ data. “DEV-0270 exploits high severity vulnerabilities to gain access to devices and has been known to exploit newly discovered vulnerabilities early on,” Microsoft said in the alert posted in the Security Blog was published.

Search for vulnerable systems

For the Microsoft Security Threat Intelligence team, one factor, in particular, was new and ominous in discovering the group’s activity: the attackers initially targeted victims, their servers, and devices for vulnerabilities in Microsoft Exchange Server, Fortinet FortiGate SSL-VPN, and Apache -Log4j are vulnerable and then use Windows’ own BitLocker security tool to harm their victims. “DEV-0270 leverages living-off-the-land binaries (LOLBINs) for credential detection and access throughout the attack chain. This extends to abusing the built-in BitLocker tool to encrypt files on compromised devices .” The use of BitLocker and DiskCryptor by Iranian actors was first discovered in early May this year.

The attackers elevate system-level privileges, which also allows them to disable Microsoft Defender and other antivirus software to evade their detection. “The threat group commonly uses native WMI, net, CMD, and PowerShell commands and registry configurations to maintain stealth and operational security,” Microsoft explained. “They also install and disguise their custom binaries as legitimate processes to hide their presence.”

To protect yourself from these attackers, Microsoft recommends installing all patches offered, checking passwords for security, and carrying out regular data backups.

Recent Posts

GameStop boss: Game disks are completely irrelevant

GameStop does not see itself under pressure from the foreseeable end of physical PlayStation games.…

19 hours ago

Linux kernel update leads to performance decline on AMD GPUs

An upcoming Ubuntu kernel update brutally slows down AMD GPUs: The update to version 7.0.0-28.28…

19 hours ago

Tasteless but expensive: luxury gold cell phones honor Messi and Ronaldo

The luxury brand Caviar is celebrating the 2026 World Cup with exclusive special editions. The…

19 hours ago

Switch 1 & 2: Nintendo may be working on a smart universal dock

A patent that has surfaced suggests that Nintendo could be working on a universal dock…

19 hours ago

Steam Sales: Valve reveals dates for all discount promotions until July 2027

The dates for all upcoming sales on Valve's gaming platform Steam in the first half…

19 hours ago

Spotify: Former premium function is now free for all users

Spotify is unlocking a previous premium feature for all users. From now on, managed user…

19 hours ago