Colombia and Mexico: BitLocker ransomware
Kaspersky analyzed two cases in Colombia and Mexico where attackers used BitLocker and corporate printers to print ransom notes.
Kaspersky investigated two ransomware incidents in Latin America between May and June 2026 that hit organizations in Colombia and Mexico. In both cases, attackers used BitLocker to encrypt systems and corporate printers to print ransom notes. The company also tied the activity to internet-exposed services, misconfigurations, and legitimate admin tools.
Kaspersky investigated two ransomware incidents in Latin America between May and June 2026 that hit organizations in Colombia and Mexico. In both cases, attackers used BitLocker to encrypt systems and corporate printers to print ransom notes.
How they got in
According to the analysis cited by RTM World, the attacks relied mainly on internet-exposed services, security misconfigurations and legitimate administrative tools, rather than custom malware. In Colombia, the attackers reportedly entered through an internet-exposed remote access service connected to a server that managed an 8 TB storage device holding critical business data.
In Mexico, the source says, without official confirmation, that a group identifying itself as XEntry Team may have reached the network through a misconfigured Microsoft SQL Server and credentials exposed in public code.
Operational signs and the technique used
The technical analysis by Securelist, cited by HelpRansomware, explicitly identifies the group as XEntry Team and describes an extortion model that demands intentionally small ransoms. It also says the actor does not operate under a classic ransomware franchise and relies only on tools already present in the victims' Windows domains.
Indicators observed included a blue screen with the text Hacked by XEntry Team, the sudden failure of domain credentials and the automatic printing of ransom notes from corporate printers within hours of BitLocker being activated.
The same analysis highlights abuse of BitLocker, Group Policy, remote access services such as RDP and remote management tools already deployed in the Windows domain. That approach lowers costs and makes it harder for traditional controls to flag the activity as malicious.
What Kaspersky said should be closed off
Through Securelist, Kaspersky recommended keeping all BitLocker recovery keys in Active Directory or MDM with alerts for unexpected encryption, removing direct internet exposure for RDP and MSSQL, requiring multifactor authentication, restricting who can edit Group Policy objects, and auditing every change.
Italian and Spanish versions of the same technical advisory reflect a consistent account, with two incidents in Mexico in May 2026 and Colombia in June 2026, under the same XEntry signature, exclusive use of legitimate Windows environment tools and low-value ransom demands. That confirms a minimum scope of two Latin American countries.
In parallel, Flare identified ransomware activity linked to Kazu with new victim postings in Latin America after first observing an attack on an Italian telemedicine provider. The analysis cited by Help Net Security says those new victim postings in the region were in the health sector.
CrowdStrike, meanwhile, documented in 2023 LATAM malware families including Mispadu, Grandoreiro, Mekotio, Casbaneiro, Metamorfo and Astaroth, aimed mainly at Spanish and Portuguese-speaking users at financial institutions in Latin America. It also described common TTPs such as multi-tier structures with a downloader and main payload, Delphi used in core components, and obfuscation through bloated files larger than 100 MB.
Sources
- LATAM Malware Variants - 2023 Technical Updatescrowdstrike.com· CrowdStrike
- BitLocker Extortion: The XEntry Printer Ransom Schemehelpransomware.com· HelpRansomware / Securelist (Kaspersky)
- Prints of darkness: Hackers printing demands during ransomware campaigns across Latin America — Kasperskykaspersky.com· Kaspersky
- Ransomware gangs go after EMEA healthcare's supply chainhelpnetsecurity.com· Help Net Security
- Extorsión BitLocker: el esquema XEntry con impresorashelpransomware.com· HelpRansomware / Securelist (Kaspersky)
- Estorsione BitLocker: lo schema XEntry con le stampantihelpransomware.com· HelpRansomware / Securelist (Kaspersky)
- Ransomware Attacks Using Corporate Printers Found in LATAMrtmworld.com· RTM World



