- Kaspersky described ransomware cases in Colombia and Mexico where attackers exploited misconfigured systems
- Victims’ drives were locked with BitLocker, ransom notes printed via office printers
- New group “XEntry Team” took responsibility; misconfigurations remain a major risk of breakage
In true Hollywood fashion, cybercriminals have started using office printers to notify victims that they have been hit by ransomware.
Security researchers at Kaspersky have described two recent incidents, one in Colombia and one in Mexico, where cybercriminals exploited misconfigured systems.
However, both had the same result – the attackers used BitLocker to lock key drives, then used office printers to print their ransom notes.
XEntry Team claims the attacks
In Colombia, a machine with eight terabytes of mission-critical data had its Endpoint Protection Platform (EPP) disabled due to compatibility issues. It also had an Internet-exposed Remote Desktop Protocol (RDP) running, which allowed relatively easy access for the attackers.
Mexico’s attack was somewhat different. Three months before starting, the attackers discovered misconfigurations in the MSSQL service that gave them privileged access to the target environment. They spent the next few months lowering server security settings, dropping web shells, and although some triggered EPP alerts, the victims never thoroughly investigated.
In the Colombia case, the attackers asked for just $3,000, an offer the victims quickly accepted. Therefore, there was not enough forensic evidence left to conduct a thorough investigation. Kaspersky did not say how much money the attackers asked for in the Mexico case, or whether or not the victims ended up paying.
In both cases, the attackers did not exploit a vulnerability or even target an unwitting employee with social engineering. Instead, they exploited misconfigurations, which remain one of the biggest causes of breaches and data leaks.
“We strongly recommend configuring RDP in strict accordance with cybersecurity best practices to prevent unauthorized access,” Kaspersky warned. “This is particularly critical: according to our Global Report: Anatomy of a Cyber World, more than 13% of incidents are related to policy violations and configuration errors, confirming that misconfigurations continue to pose a significant risk.”
The attacks were carried out by a group calling itself the “XEntry Team”. There are no previous reports of this group, and it is either a previously unknown threat actor or a simple rebrand.
The best antivirus for all budgets
Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews and opinions in your feeds.



