On November 27, 2025, Chris Horlacher’s primary workstation — a high-end CLX desktop — suffered a Blue Screen of Death (BSOD) during the uninstallation of Ableton, an audio recording suite. The machine has not booted normally since. CrowdStrike’s Enterprise EDR recorded the incident, and Horlacher’s independent security analyst recommended a full forensic investigation.
In December 2025, Equibit Group Ltd. engaged Duriva, a Mexico City-based digital forensics firm, to perform a comprehensive analysis. The computer was physically delivered to their offices on January 9, 2026.
Initial Promise, Then Evasion
Duriva’s CEO, Jocsan Laguna, initially appeared engaged. The firm used professional tools (Oxygen Forensic Detective and Magnet AXIOM) and even additional tools to conduct the analysis.
On February 3, Jocsan informed Horlacher that they had “retrieved several elements that appear to be related to the lawsuit” and asked for details regarding suspicious system behavior and events.

The next day the CEO informed Chris of additional forensic tools they deployed in order to complete the analysis and schedules a video call to explain what Duriva found.

Almost immediately afterward, communications became erratic. WhatsApp messages between Horlacher and Duriva began experiencing severe delays — sometimes arriving more than 24 hours late. This interference started precisely when the investigation appeared to be producing significant findings.
The Collapse
- Scheduled technical debrief meetings were repeatedly postponed or cancelled.
- The promised video walkthrough was delivered with no audio.
- Communication became sporadic and evasive.
- On February 6, Duriva issued a final “Dictamen Forense” that attributed the entire incident to normal Ableton uninstallation behavior, largely dismissing the possibility of malicious activity.
Duriva later requested that Horlacher retrieve the computer. When he pushed back, stating that the work was incomplete and that he still expected a proper technical debrief on their findings, Duriva went completely silent and has not contacted him again as of this writing. The computer itself remains in Duriva’s posession.
The WhatsApp Delays
The timing of the severe WhatsApp message delays is particularly noteworthy. Multiple lawsuits, investigations, and technical reports worldwide have raised credible concerns that Meta (WhatsApp) has compromised or selectively weakened end-to-end encryption in cases involving powerful state or institutional interests.
Relevant examples include:
- Forbes – New WhatsApp Warning As Encryption Is ‘Bypassed’
- Forbes – ‘Massive Security Vulnerability’—Do You Need To Stop Using WhatsApp?
- Electronic Frontier Foundation – Don’t Let Encrypted Messaging Become a Hollow Promise
- Wired – A New Era of Attacks on Encryption Is Starting to Heat Up
- Detained in Dubai – Second Flight Attendant Detained in Dubai Over WhatsApp Image
The sudden onset of consistent message delivery failures right as Duriva claimed to have discovered something significant raises legitimate questions about possible interception or manipulation of communications related to this forensic analysis.
Implications
The full sequence — promising discoveries → sudden communication problems → meeting avoidance → dismissive final report → complete silence after being challenged — raises serious concerns about possible interference in the evidence-gathering process.
One particularly compelling explanation is that Duriva encountered artifacts consistent with a Microsoft-signed payload pushed onto the system (possibly via Windows Update mechanisms). This would align with previous documented incidents in which Horlacher observed suspicious Microsoft updates being forced onto his machines. A signed payload would be extremely difficult for standard forensics tools to flag as malicious, while still capable of causing deep system instability such as the observed BSOD, Winsock corruption, and driver conflicts.
If this hypothesis is correct, it would explain both the initial excitement from the forensics team and their subsequent withdrawal. Sophisticated state actors increasingly favor signed malware precisely because it is designed to evade detection and complicate attribution.
This incident fits a broader pattern of obstruction and sabotage that Equibit Group Ltd. has documented since Chris Horlacher filed suit against CSIS. It further demonstrates the extraordinary challenges of obtaining independent technical validation when powerful actors are allegedly involved.
The public documentation continues.
Full lawsuit materials and timeline: equibitlawsuit.com
Never miss a new article. Subscribe for weekly updates.
