View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

Cyberattack Exposes Data of 31,000 in Liechtenstein’s Register

💥 BREACHES & INCIDENTS

  • Cyberattack Exposes Data of 31,000 in Liechtenstein’s Register of Company Beneficiaries Liechtenstein’s register of people behind companies and foundations was breached, exposing data of 31,000 individuals.
    • Applies to Liechtenstein’s register of economic beneficiaries behind companies, foundations, and trusteeships
    • Data of approximately 31,000 people was accessed during a cyberattack overnight from Wednesday to Thursday
    • Attack detected on Thursday; system taken offline and secured with no evidence of data alteration or deletion
    • Register supports anti-money laundering and counter-terror financing efforts in the financial sector
    • Liechtenstein is a small nation with a significant financial industry central to its economy 📎 Coverage: securityweek.com · 👁 via SecurityWeek

🕵️ RESEARCH & DEEP DIVES

  • Russian DOUBLECUP ClickFix service hides malware in browser cache PNG images DOUBLECUP uses ClickFix attacks to hide malware in browser cache images and deliver payloads.

    • Targets Windows and macOS devices via browser cache PNG images
    • Uses ClickFix attacks with fake CAPTCHA prompts on sites mimicking NetSuite, Odoo, HubSpot, Salesforce
    • Malware embedded in cached PNG images extracted using findstr or certutil commands
    • Delivers CountLoader info stealer and DeviceManager RAT with blockchain-based C2 retrieval
    • Operators use Go-based tool to configure campaigns and generate code for multiple browsers 📎 Coverage: bleepingcomputer.com · 👁 via BleepingComputer
  • Fake Roblox Xeno script launcher spreads infostealer and RAT malware Fake Xeno Executor installers infect Roblox players with info-stealing RAT malware.

    • Targets Roblox players using fake Xeno Executor script launcher installers
    • Malware delivered via ZIP or self-extracting archives mimicking legitimate Xeno files
    • Initial loader checks Java environment, then runs obfuscated Java payload for C2 communication
    • Final payload steals browser data, online account credentials, crypto wallets, and enables remote control
    • Capabilities include keylogging, screenshots, webcam access, file transfer, and PowerShell execution 📎 Coverage: bleepingcomputer.com · 👁 via BleepingComputer

🔓 CVEs & KEV

  • Other: 20 CVEs (worst 9.8)
  • N-able: 1 CVEs (no scores, 1 in KEV)

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check