How victims first discovered the intrusion
In both incidents the immediate, visible sign of compromise was identical: users saw a padlock icon next to drives in Windows Explorer, indicating BitLocker had locked the volume and a recovery key was required to regain access. In the Mexico case, users also encountered a blue screen reading "Hacked by XEntry Team" and found that their credentials no longer worked; in both cases ransom notes began printing from office printers hours after encryption activity completed.
Colombia incident: exposed RDP, an 8 TB drive, and a $3,000 demand
In June, attackers abused an internet-exposed Remote Desktop Protocol (RDP) service on a system attached to an 8 TB storage device containing mission-critical financial data. With control of the endpoint and manipulated credentials, the actor enabled BitLocker only on the drive holding the financial information, then locked it and used the company’s printers to produce ransom notes. Communication with the attackers showed a demand for $3,000. The victim expedited restoration of the disk before a forensic team could collect evidence, preventing further analysis of artifacts from the intrusion. Responders reported that EPP protection had been disabled on the affected system due to application compatibility issues, a condition that reduced central visibility and eased attacker validation and execution of tools.
Mexico incident: XEntry Team, a misconfigured MSSQL, and RMM abuse
The May intrusion in Mexico began with exploitation of a misconfigured Microsoft SQL Server instance whose credentials were recovered from code accidentally published on GitHub. The database engine in use was Microsoft SQL Server 2019.0150.2160.04, which had been misconfigured to allow operating system command execution via the xp_cmdshell extended stored procedure. The intruder verified and maintained access for roughly three months, manipulating the web server, deploying web shells, and—despite EPP alerts—remaining uninvestigated.
Attackers used the MSSQL foothold to scan the environment and deploy ManageEngine’s Endpoint Central RMM to establish persistence, followed by additional RMM tools such as Mesh Agent and Tactical RMM. Those RMM agents created scheduled tasks that enabled BitLocker and encrypted disks individually, generating a key for each system. In mid-May the adversary pushed a Group Policy Object (GPO) that deployed activation and encryption tasks and propagated RMM installations; the campaign initially targeted critical systems and then spread to all systems synchronized with the domain controller. Ransom notes began printing from office printers shortly after these actions.
Abuse of built-in tools, printers, and low-dollar extortion as an operational choice
Both incidents demonstrate an operational pattern: adversaries avoided contracting with established ransomware groups and instead relied on built-in Microsoft tooling—BitLocker and Group Policy—to effect encryption, and on office printers to deliver ransom notes. The attacks reused phrasing about "reputation" and guarantees in their notes, suggesting a possible link between the cases even if direct attribution remains unresolved. The advisory also recalls an earlier threat—ShrinkLocker—that similarly leveraged BitLocker.
What this means for technologists, IT managers, and policymakers
- Technologists and security teams: prioritize centralized log collection and timely alert management on protected resources. The Mexico case shows how EPP alerts can be generated yet not acted upon; the Colombia case shows how disabled EPP creates blind spots. Monitor for abuse of xp_cmdshell and for unauthorized RMM installations and scheduled tasks that enable BitLocker.
- Procurement and IT managers (affected enterprises): avoid leaving RDP and database services internet-exposed without strict controls; review compatibility-driven EPP exceptions that remove endpoint protections. Misconfigurations—such as an exposed RDP or an MSSQL instance permitting xp_cmdshell—were decisive enablers in these intrusions.
- Policymakers and regulators: note the operational shift toward low-ransom, in-house encryption campaigns using legitimate tools and physical printouts. The source cites its Global Report: Anatomy of a Cyber World finding that "more than 13% of incidents are related to policy violations and configuration errors" and that "more than 20% of incidents involved the abuse of RMM (Remote Monitoring and Management) tools for execution and C2 strategies." Those figures frame the risk posed by misconfiguration and legitimate-tool abuse.
These two investigations leave a clear operational footprint: internet-exposed services, disabled or ignored security controls, misuse of legitimate remote-management tooling, and the novel twist of using office printers as the physical channel for ransom notification. Detection signatures the responders associated with the activity include Trojan.Multi.Agent.gen, Trojan.Win32.GenAutorunMsSqlServerCommandRun.a, Trojan.Win32.Generic, and Exploit.Win32.SCShell.a.
The record produced by these cases ends on a practical note: preserving forensic evidence and enforcing strict configuration controls matter as much as any defensive technology. The incidents lay bare how modest demands—$3,000 in one case—and common administrative errors can combine to yield outsized operational disruption. The remaining question, given the echoed language in both ransom notes, is whether similarity of phrasing reflects a single actor refining a low-cost extortion model or merely a copycat tactic; investigators and defenders will need preserved evidence to tell the difference.
https://securelist.com/new-extortion-scheme-printers-bitlocker/120718/




