Mexico: Ransomware Used BitLocker
Kaspersky linked Mexico and Colombia extortion cases to BitLocker and printed ransom notes. In Mexico, access may have started with MSSQL.
Between May and June 2026, Kaspersky investigated several extortion cases in Colombia and Mexico in which attackers encrypted devices with BitLocker and used corporate printers to print ransom notes. In the Mexican case, the group identifying itself as XEntry Team allegedly entered through a misconfigured Microsoft SQL server and exposed credentials in public code.
Between May and June 2026, Kaspersky investigated several extortion incidents in Colombia and Mexico in which attackers encrypted drives with BitLocker and used corporate printers to print ransom notes. According to the company’s regional statement, the tactic was meant to raise psychological pressure inside organizations.
The Mexican case and the access chain
In one of the incidents analyzed in Mexico, researchers identified a group calling itself XEntry Team. According to TrendTIC and Kaspersky’s technical analysis, the initial access came through a misconfigured Microsoft SQL server after the attackers obtained access credentials exposed in publicly available code. Securelist Brasil added that the credentials were pulled from code uploaded to GitHub without security measures.
According to those analyses, the group remained inside the environment for about three months. During that period, it gradually weakened the web server’s protections before triggering BitLocker and taking over the corporate printers to launch the printed notes.
What the victims saw
For the Mexican case, Securelist said the victims saw a blue screen with the text "Hacked by XEntry Team," a sudden drop in domain credentials, and then the automatic start of ransom-note printing on office printers hours later. That sequence, the publication said, points to control over both Windows systems and print queues.
Securelist’s technical write-up also says XEntry Team asks for intentionally small ransom payments and relies almost entirely on tools already present on the network, such as BitLocker, exposed services and printers. It reportedly did not deploy a dedicated ransomware binary or work with a known RaaS operation.
Regional context
SC World described XEntry Team as a new group tied to this extortion pattern in Colombia and Mexico, but said the attacks did not involve specific vulnerability exploits or phishing campaigns. Instead, they relied on RDP misconfigurations in Colombia and MSSQL in Mexico.
A context analysis published by Carmona.mx stressed that XEntry Team has no documented prior history and that the Colombia and Mexico cases fit a broader regional pattern. According to that text, more than 13% of the incidents studied by Kaspersky are linked to policy violations and configuration errors, underscoring the role of exposed services in this campaign.
An independent technical summary from Skyport Systems agreed that the actor identified as XEntry Team gained initial access by exploiting a misconfigured MSSQL server and credentials extracted from code published on GitHub, reinforcing the view that this was abuse of exposed services rather than exploitation of specific CVEs.
Sources
- Хакеры в Колумбии и Мексике шифровали BitLocker и печатали, требуя выкупtechora.ru· Techora / Kaspersky Lab coverage
- Extorsión BitLocker: el esquema XEntry con impresorashelpransomware.com· HelpRansomware (republica Securelist)
- Kaspersky Security Services Identifies Ransomware Actors Using BitLocker and Printers in Latin Americainsight.tmcnet.com· TMCnet Insight
- Kaspersky alerta sobre una creciente táctica de ransomware: hackers imprimen demandas de rescate durante ataques en América Latinalatam.kaspersky.com· Kaspersky LATAM
- BitLocker Extortion: The XEntry Printer Ransom Schemehelpransomware.com· HelpRansomware (republica Securelist)
- New ransomware group uses printers to deliver ransom notesscworld.com· SC World
- Errores de configuración que alimentan el ransomware: lecciones de Colombia y Méxicocarmona.mx· Carmona.mx
- Nova extorsão com BitLocker: abuso de RDP, MSSQL e RMMsecurelist.com.br· Securelist Brasil / Kaspersky
- Expertos alertan sobre una creciente táctica de ransomware hackers imprimen demandas de rescate durante ataques en América Latinatrendtic.cl· TrendTIC
- Ransomware Actors Exploit BitLocker and Corporate Printers in Latin Americaskyportsystems.net· Skyport Systems



