CiberLATAMbywhalemate

Mexico: Ransomware Used BitLocker

Kaspersky linked Mexico and Colombia extortion cases to BitLocker and printed ransom notes. In Mexico, access may have started with MSSQL.

Whalemate Labs · AI-assisted researchJul 28, 20262 min read

Between May and June 2026, Kaspersky investigated several extortion cases in Colombia and Mexico in which attackers encrypted devices with BitLocker and used corporate printers to print ransom notes. In the Mexican case, the group identifying itself as XEntry Team allegedly entered through a misconfigured Microsoft SQL server and exposed credentials in public code.

Between May and June 2026, Kaspersky investigated several extortion incidents in Colombia and Mexico in which attackers encrypted drives with BitLocker and used corporate printers to print ransom notes. According to the company’s regional statement, the tactic was meant to raise psychological pressure inside organizations.

The Mexican case and the access chain

In one of the incidents analyzed in Mexico, researchers identified a group calling itself XEntry Team. According to TrendTIC and Kaspersky’s technical analysis, the initial access came through a misconfigured Microsoft SQL server after the attackers obtained access credentials exposed in publicly available code. Securelist Brasil added that the credentials were pulled from code uploaded to GitHub without security measures.

According to those analyses, the group remained inside the environment for about three months. During that period, it gradually weakened the web server’s protections before triggering BitLocker and taking over the corporate printers to launch the printed notes.

What the victims saw

For the Mexican case, Securelist said the victims saw a blue screen with the text "Hacked by XEntry Team," a sudden drop in domain credentials, and then the automatic start of ransom-note printing on office printers hours later. That sequence, the publication said, points to control over both Windows systems and print queues.

Securelist’s technical write-up also says XEntry Team asks for intentionally small ransom payments and relies almost entirely on tools already present on the network, such as BitLocker, exposed services and printers. It reportedly did not deploy a dedicated ransomware binary or work with a known RaaS operation.

Regional context

SC World described XEntry Team as a new group tied to this extortion pattern in Colombia and Mexico, but said the attacks did not involve specific vulnerability exploits or phishing campaigns. Instead, they relied on RDP misconfigurations in Colombia and MSSQL in Mexico.

A context analysis published by Carmona.mx stressed that XEntry Team has no documented prior history and that the Colombia and Mexico cases fit a broader regional pattern. According to that text, more than 13% of the incidents studied by Kaspersky are linked to policy violations and configuration errors, underscoring the role of exposed services in this campaign.

An independent technical summary from Skyport Systems agreed that the actor identified as XEntry Team gained initial access by exploiting a misconfigured MSSQL server and credentials extracted from code published on GitHub, reinforcing the view that this was abuse of exposed services rather than exploitation of specific CVEs.

Sources

View all