The threat actors deployed BitLocker in multiple attacks and used corporate printers to deliver ransom notes directly to affected organizations.
Between May and June 2026, Kaspersky Security Services experts investigated a series of ransomware incidents targeting organizations in Colombia and Mexico. The attacks involved misconfigurations, BitLocker encryption, and the abuse of corporate printers to deliver ransom demands. In the analyzed cases, the attackers informed the targeted organizations that their infrastructure had been compromised and that payment was required to restore access to their data. Affected users first noticed a padlock icon next to their drives in Windows Explorer, indicating that the systems had been encrypted with BitLocker and that the files were no longer accessible.
One of the investigated incidents took place in Colombia, where attackers gained entry through an internet-exposed remote access service linked to a server connected to an 8 TB storage device containing business-critical data. After establishing control of the environment and altering user credentials, the threat actor leveraged BitLocker to encrypt the drive, which primarily stored financial information. The attackers then rendered the data inaccessible and used the organization’s own printers to distribute ransom demands.
Ransomware note distributed by a threat actor during one of the attacks
In a separate incident in Mexico, Kaspersky experts found that attackers calling themselves the “XEntry team” gained initial access through a misconfigured Microsoft SQL server after obtaining login credentials exposed in publicly available code. From there, they moved beyond the database environment, weakened web server protections, and established persistent access across the organization’s infrastructure for several months before the intrusion was detected. The compromise ultimately became visible to employees when their machines displayed a blue screen bearing the message “Hacked by XEntry Team,” while their usual credentials no longer allowed them to access their systems.
“These incidents highlight a pragmatic approach to ransomware,” said Eduardo Chavarro Ovalle, Kaspersky digital forensic and incident response group manager. “Instead of relying on sophisticated malware, attackers are taking advantage of exposed services, weak configurations, and legitimate administrative tools already present in the environment to encrypt data and pressure victims into paying. In some cases, they also use channels such as printed ransom notes to exert psychological pressure on victims and reinforce the urgency of their demands. To defend against this type of intrusion, organizations should centralize and secure logs, closely monitor alerts, and rapidly investigate any signs of unauthorized access.”
Although the ransom notes do not conclusively establish that the same actor was behind these incidents, similarities in wording, delivery method and communication style may indicate a possible connection.
More details available on Securelist.com.