A new extortion cocktail: office printers, small ransoms, and BitLocker
ID: d0a6eb01-5207-5936-8e3a-c13ebb3bce1d
STIX ID: report--d0a6eb01-5207-5936-8e3a-c13ebb3bce1d
Feed Name: Securelist by Kaspersky
This report describes two related incidents in Latin America: in Colombia attackers exploited an internet-facing RDP and disabled EPP to enable BitLocker on a critical 8 TB financial drive and printed ransom notes; in Mexico a threat actor (self-described XEntry Team) abused a misconfigured, internet-exposed MSSQL (xp_cmdshell enabled) to deploy RMM tools (ManageEngine Endpoint Central, Mesh Agent, Tactical RMM), push GPOs and scheduled tasks that enabled BitLocker across domain-synced systems and printed ransom notes. Both events highlight misconfiguration, insufficient alert handling, and living-off-the-land tactics; recommended mitigations include securing RDP/MSSQL, centralizing logs and alerts, enforcing application control, preserving forensic evidence, and restricting RMM use.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
