AUTO-UPDATED

A bizarre new malware campaign hacks your printer and forces it to print out ransomware demands

The newly identified XEntry Team is targeting organizations in Colombia and Mexico by exploiting system misconfigurations to deploy BitLocker ransomware and print physical extortion notes via office printers.

Key Points

  • Security firm Kaspersky identified two ransomware attacks in Colombia and Mexico attributed to a threat actor known as the XEntry Team.
  • Attackers gained unauthorized access by exploiting misconfigured Remote Desktop Protocol (RDP) settings and MSSQL services.
  • The perpetrators utilized BitLocker to encrypt critical data and used office printers to deliver ransom demands directly to victims.
  • In the Colombian incident, attackers successfully extorted a $3,000 payment after disabling the victim's Endpoint Protection Platform.
  • Kaspersky reports that over 13% of global security incidents stem from policy violations and configuration errors rather than software vulnerabilities.

Why it Matters

These incidents highlight that basic security hygiene, such as properly configuring RDP and database services, remains a critical defense against modern ransomware threats. Organizations that fail to address these common misconfigurations leave themselves vulnerable to attackers who prioritize exploiting existing system weaknesses over complex technical exploits.
TechRadar Published by Sead Fadilpašić
Read original