- Kaspersky detailed ransomware cases in Colombia and Mexico where attackers exploited misconfigured systems
- Victims’ drives were locked with BitLocker and ransom notes printed via office printers
- The new group “XEntry Team” claimed responsibility; misconfigurations remain a major breach risk
Cybercriminals have, in true Hollywood fashion, started using office printers to notify their victims that they have been attacked by ransomware.
Kaspersky security researchers detailed two recent incidents, one in Colombia and the other in Mexico, in which cybercriminals took advantage of misconfigured systems.
However, both achieved the same result: the attackers used BitLocker to lock the key drives, then used office printers to print their ransom notes.
The XEntry team takes responsibility for the attacks
In Colombia, a machine containing eight terabytes of critical data had its Endpoint Protection Platform (EPP) disabled due to compatibility issues. It also had a Remote Desktop Protocol (RDP) exposed to the Internet, which allowed relatively easy access for attackers.
Mexico’s attack was somewhat different. Three months before taking action, the attackers discovered configuration errors in the MSSQL service that granted them privileged access to the target environment. They spent the next few months lowering server security settings, abandoning web shells, and although some triggered EPP alarms, the victims never investigated thoroughly.
In the Colombian case, the attackers asked for just $3,000, an offer the victims quickly accepted. Therefore, there was insufficient forensic evidence to conduct a thorough investigation. Kaspersky did not say how much money the attackers demanded in the Mexican case, or whether or not the victims ended up paying.
In both cases, the attackers did not exploit a vulnerability, or even target an unaware employee with social engineering. Instead, they exploited configuration errors, which remain one of the leading causes of data breaches and leaks.
“We strongly recommend configuring RDP in strict accordance with cybersecurity best practices to prevent unauthorized access,” Kaspersky warned. “This is particularly critical: according to our global report: Anatomy of a Cyberworld, more than 13% of incidents are linked to policy violations and configuration errors, confirming that misconfigurations continue to pose a significant risk. »
The attacks were carried out by a group calling itself “XEntry Team.” There are no previous reports of this group, and it is either a previously unknown threat actor or a simple name change.
The best antivirus for every budget
Follow TechRadar on Google News And add us as your favorite source to get our news, reviews and expert opinions in your feeds.




