The newly identified XEntry Team is targeting organizations in Colombia and Mexico by exploiting system misconfigurations to deploy BitLocker ransomware and print physical extortion notes via office printers.
Key Points
- Security firm Kaspersky identified two ransomware attacks in Colombia and Mexico attributed to a threat actor known as the XEntry Team.
- Attackers gained unauthorized access by exploiting misconfigured Remote Desktop Protocol (RDP) settings and MSSQL services.
- The perpetrators utilized BitLocker to encrypt critical data and used office printers to deliver ransom demands directly to victims.
- In the Colombian incident, attackers successfully extorted a $3,000 payment after disabling the victim's Endpoint Protection Platform.
- Kaspersky reports that over 13% of global security incidents stem from policy violations and configuration errors rather than software vulnerabilities.