- Kaspersky detailed ransomware cases in Colombia and Mexico where attackers exploited misconfigured systems
- Victims’ drives were locked with BitLocker and ransom notes were printed using office printers.
- The new group “XEntry Team” claimed responsibility; misconfigurations remain a significant breach risk
Cybercriminals, in true Hollywood style, have begun using office printers to notify victims that they have been attacked by ransomware.
Kaspersky security researchers have detailed two incidents that took place recently, one in Colombia and another in Mexico, where cybercriminals took advantage of misconfigured systems.
However, both had the same result: the attackers used BitLocker to lock key drives and then used office printers to print their ransom notes.
XEntry Team takes credit for the attacks
In Colombia, a machine containing eight terabytes of mission-critical data had its endpoint protection platform (EPP) disabled due to compatibility issues. It also had a Remote Desktop Protocol (RDP) running exposed to the Internet, allowing relatively easy access for attackers.
The attack on Mexico was something different. Three months before taking action, the attackers discovered configuration errors in the MSSQL service that gave them privileged access to the target environment. They spent the next few months reducing the server’s security settings, removing web shells, and although some triggered EPP alarms, the victims never investigated further.
In the case of Colombia, the attackers asked for only $3,000, an offer that the victims quickly accepted. Therefore, there was not enough forensic evidence left to conduct a thorough investigation. Kaspersky did not say how much money the attackers asked for in the Mexico case, or whether the victims ended up paying or not.
In both cases, the attackers did not exploit a vulnerability, or even target an unwitting employee with social engineering. Instead, they took advantage of misconfigurations, which remain a leading cause of data leaks and breaches.
“We strongly recommend configuring RDP in strict accordance with cybersecurity best practices to prevent unauthorized access,” Kaspersky warned. “This is especially critical: according to our Global Report: Anatomy of a Cyber World, more than 13% of incidents are related to policy violations and configuration errors, confirming that misconfigurations continue to represent a significant risk.”
The attacks were carried out by a group calling itself “XEntry Team.” There are no previous reports of this group and it is either a previously unknown threat actor or a simple rebrand.
The best antivirus for all budgets
Follow TechRadar on Google News and add us as a preferred source to receive news, reviews and opinions from our experts in your feeds.




