XEntry Team ransomware gang prints ransom notes via office printers in Colombia and Mexico
Cybersecurity firm Kaspersky has detailed two ransomware attacks by a group called XEntry Team — one in Colombia and one in Mexico — where attackers exploited misconfigured systems. The criminals used BitLocker to lock victims' drives and then sent ransom demands directly to office printers to be physically printed out. In Colombia, a machine holding eight terabytes of mission-critical data was compromised, underscoring the danger of poorly configured endpoints.
Full text
Kaspersky detailed ransomware cases in Colombia and Mexico where attackers exploited misconfigured systems
Victims’ drives were locked with BitLocker, ransom notes printed via office printers
New group “XEntry Team” claimed responsibility; misconfigurations remain a major breach risk
Cybercriminals have, in true Hollywood fashion, started using office printers to notify victims they were struck by ransomware .
Security researchers at Kaspersky have detailed two incidents which recently took place, one in Colombia, and one in Mexico, where cybercriminals took advantage of misconfigured systems.
However both had the same outcome - the attackers used BitLocker to lock down key drives, and then used office printers to print out their ransom notes.
XEntry Team claims the attacks
In Colombia, a machine containing eight terabytes of mission-critical data had its Endpoint Protection Platform (EPP) disabled due to compatibility issues. It also had an internet-exposed Remote Desktop Protocol (RDP) running, which enabled relatively easy access for the attackers.
The Mexico attack was somewhat different. Three months before springing to action, the attackers discovered misconfigurations in the MSSQL service which granted them privileged access to the target environment. They spent the next couple of months lowering the server’s security settings, dropping web shells, and even though some triggered EPP alarms, the victims never investigated thoroughly.
In the Colombia case, the attackers asked for only $3,000, an offer the victims quickly accepted. Therefore, there was not enough forensic evidence left behind to conduct a thorough investigation. Kaspersky did not say how much money the attackers asked for in the Mexico case, or if the victims ended up paying or not.
In both cases, the attackers did not exploit a vulnerability, or even target an oblivious employee with social engineering. Instead, they exploited misconfigurations, which continue to be one of the biggest causes of breaches and data leaks.
“We strongly recommend configuring the RDP in strict accordance with cybersecurity best practices to prevent unauthorized access,” Kaspersky warned. “This is especially critical: according to our Global Report: Anatomy of a Cyber World, more than 13% of incidents are related to policy violations and configuration errors, confirming that misconfigurations continue to pose a significant risk.”
The attacks were done by a group calling itself “XEntry Team”. There are no prior reports of this group, and it is either a previously unknown threat actor, or a simple rebrand.
💻 Technology
Pay ransomware hackers and 37% of victims face a second demand — Proofpoint 2026 report
TechRadar · 15h ago
💻 Technology
Pay a Hacker's Ransom and They'll Likely Come Back for More, Research Confirms
TechCrunch · 2d ago
💻 Technology
Ransomware Attack on Ecopetrol: 3,300 Accounts Hit, Encryptor Blocked
TechRadar · 4d ago
💻 Technology
Nearly half of ransomware victims pay up as UK plans ban on public sector payments
Ars Technica · 4d ago
💻 Technology
Qilin and The Gentlemen gangs launched nearly 600 ransomware attacks in Q2 2026
TechRadar · 4d ago
🪙 Crypto
Kaspersky uncovers malware framework stealing crypto via trojanized GitHub apps
Cointelegraph · 6d ago
💻 Technology
Pay ransomware hackers and 37% of victims face a second demand — Proofpoint 2026 report
TechRadar · 15h ago
💻 Technology
Pay a Hacker's Ransom and They'll Likely Come Back for More, Research Confirms
TechCrunch · 2d ago
💻 Technology
Ransomware Attack on Ecopetrol: 3,300 Accounts Hit, Encryptor Blocked
TechRadar · 4d ago
Do companies do enough to protect themselves against ransomware attacks?
Comments
No comments yet
Comments
No comments yet — be the first to weigh in 👇
No comments yet. Be the first!