Colombia: ransomware using BitLocker
Kaspersky found attacks in Colombia and Mexico that encrypted systems with BitLocker and printed ransom notes from corporate printers.
Kaspersky investigated a series of ransomware incidents in Colombia and Mexico between May and June 2026 in which attackers combined exposed services, BitLocker encryption, and corporate printers to distribute ransom notes inside the organizations.
Kaspersky Security Services investigated a series of ransomware incidents in Colombia and Mexico between May and June 2026 in which attackers combined misconfigurations, BitLocker encryption, and corporate printers to deliver ransom notes inside the organizations.
Initial access and encryption
In one of the cases analyzed in Colombia, initial access came through an internet-exposed remote access service. That service was tied to a server connected to an 8 TB storage device holding critical financial information. After getting in, the attackers changed user credentials, enabled BitLocker to encrypt the volume, and used corporate printers to distribute ransom notes.
Specialized coverage published in July also described a similar incident in Colombia, with the same entry point through exposed remote access and the subsequent encryption of a server linked to an 8 TB device containing information critical to business operations.
Technique and attribution
According to technical analysis cited by HelpRansomware from Securelist, the campaign in Colombia and Mexico was attributed to the actor identified as XEntry Team. The group leaves a blue screen with the message "Hacked by XEntry Team" and, hours after encryption, prints ransom notes.
The same analysis says that in both incidents, Mexico in May and Colombia in June 2026, victims first noticed a padlock icon next to the drives in Windows Explorer and a prompt asking for the BitLocker recovery key. That confirmed no custom malware had been deployed, only Windows' native encryption.
It was also detailed that the attackers abused legitimate mechanisms already present in the networks, such as RDP, MSSQL, remote management tools, and Group Policy, to spread encryption from critical systems to the rest of the devices joined to the domain controller. The goal was to maximize impact without needing ransomware binaries.
Regional scope and defenses
TrendTIC reported in July 2026 on a campaign that affected organizations in Colombia and Mexico and noted that printing ransom demands is an emerging tactic in the region. HelpRansomware added that XEntry Team deliberately asks for small ransom amounts, in line with the trend Kaspersky observed in these campaigns, something that can speed up payment and reduce public visibility of the incidents.
Carmona.mx said that in the Colombia and Mexico cases, no exploits for specific vulnerabilities or targeted phishing campaigns were identified. The source of the intrusion was misconfiguration and poor management of internet-exposed services, reinforcing the importance of exposure management and weak hardening.
The technical recommendations drawn from the analysis include storing BitLocker recovery keys in Active Directory or MDM with alerts when encryption is enabled on unexpected devices, removing RDP and MSSQL from direct internet exposure and protecting them behind a VPN or bastion with MFA, and limiting who can modify Group Policy objects while auditing every change.
Sources
- La llegada de los “cárteles” a la ciberseguridadinversorlatam.com· Inversor Latam
- Prints of darkness: Hackers printing demands during ransomware campaigns across Latin Americakaspersky.com· Kaspersky
- Expertos alertan sobre una creciente táctica de ransomware: hackers imprimen demandas de rescate durante ataques en América Latinatrendtic.cl· TrendTIC
- Extorsión BitLocker: el esquema XEntry con impresorashelpransomware.com· HelpRansomware
- BitLocker Extortion: The XEntry Printer Ransom Schemehelpransomware.com· HelpRansomware
- Хакеры в Колумбии и Мексике шифровали BitLocker и печатали, требуя выкупtechora.ru· Techora.ru
- Errores de configuración que alimentan el ransomware: lecciones de Colombia y Méxicocarmona.mx· Carmona.mx



