AI-generated · no human review · verify operationally critical claims against the linked primary source.how it works →
XEntry Team
actor
· actor:xentry-teamsingle-source
Financially-motivated BitLocker-abuse extortion actor named from a May 2026 Mexico incident whose victims' screens displayed 'Hacked by XEntry Team' (Kaspersky GERT, 2026-07-21): initial access via a misconfigured Microsoft SQL Server (xp_cmdshell), persistence via legitimate RMM tools (ManageEngine Endpoint Central, Mesh Agent, Tactical RMM) and web shells, BitLocker deployed via GPO for encryption-for-impact, small ransom (~USD 3,000), ransom notes printed on office printers. Kaspersky documented a separate June 2026 Colombia BitLocker-extortion case (RDP-based) with which it assesses a POSSIBLE but unconfirmed link (ransom-note wording/delivery similarities; 'do not reveal a clear connection between the actors'). ShrinkLocker BitLocker-abuse lineage.
6 techniques observed across 1 entry — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.1 · compare on the matrix · Navigator layer (JSON)
Initial Access TA0001
T1133External Remote Services×1
Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect to internal enterprise network resources from external locations. There are often remote service gateways that manage connections and credential authentication for these services. Services such as Windows Remote Management and VNC can also be used externally.
Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect to internal enterprise network resources from external locations. There are often remote service gateways that manage connections and credential authentication for these services. Services such as Windows Remote Management and VNC can also be used externally.
Adversaries may abuse SQL stored procedures to establish persistent access to systems. SQL Stored Procedures are code that can be saved and reused so that database users do not waste time rewriting frequently used SQL queries. Stored procedures can be invoked via SQL statements to the database using the procedure name or via defined events (e.g. when a SQL server application is started/restarted).
Adversaries may backdoor web servers with web shells to establish persistent access to systems. A Web shell is a Web script that is placed on an openly accessible Web server to allow an adversary to access the Web server as a gateway into a network. A Web shell may provide a set of functions to execute or a command-line interface on the system that hosts the Web server.
T1484.001Domain or Tenant Policy Modification: Group Policy Modification×1
Adversaries may modify Group Policy Objects (GPOs) to subvert the intended discretionary access controls for a domain, usually with the intention of escalating privileges on the domain. Group policy allows for centralized management of user and computer settings in Active Directory (AD). GPOs are containers for group policy settings made up of files stored within a predictable network path `\<DOMAIN>\SYSVOL\<DOMAIN>\Policies\`.
T1484.001Domain or Tenant Policy Modification: Group Policy Modification×1
Adversaries may modify Group Policy Objects (GPOs) to subvert the intended discretionary access controls for a domain, usually with the intention of escalating privileges on the domain. Group policy allows for centralized management of user and computer settings in Active Directory (AD). GPOs are containers for group policy settings made up of files stored within a predictable network path `\<DOMAIN>\SYSVOL\<DOMAIN>\Policies\`.
An adversary may use legitimate remote access tools to establish an interactive command and control channel within a network. Remote access tools create a session between two trusted hosts through a graphical interface, a command line interaction, a protocol tunnel via development or management software, or hardware-level access such as KVM (Keyboard, Video, Mouse) over IP solutions. Desktop support software (usually graphical interface) and remote management software (typically command line interface) allow a user to control a computer remotely as if they are a local user inheriting the user or software permissions. This software is commonly used for troubleshooting, software installation, and system management. Adversaries may similarly abuse response features included in EDR and other defensive tools that enable remote access.
Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources. They can attempt to render stored data inaccessible by encrypting files or data on local and remote drives and withholding access to a decryption key. This may be done in order to extract monetary compensation from a victim in exchange for decryption or a decryption key (ransomware) or to render data permanently inaccessible in cases where the key is not saved or transmitted.
Kaspersky's GERT incident-response team documented two 2026 extortion incidents in Latin America that abuse native Windows BitLocker for encryption-for-impact rather than deploying a conventional ransomware family — a living-off-the-land model that leaves no bespoke encryptor for signature-based detection (Kaspersky, 2026-07-21). In the first case (Colombia, June), initial access was an internet-exposed RDP service on a host attached to an 8 TB store of mission-critical data; after manipulating credentials the attacker enabled BitLocker on the drive and demanded roughly USD 3,000. In the second case (Mexico, May) — whose victims' screens displayed "Hacked by XEntry Team" — initial access was a misconfigured Microsoft SQL Server whose xp_cmdshell extended stored procedure allowed OS command execution; the operators established persistence through legitimate RMM suites (ManageEngine Endpoint Central, Mesh Agent, Tactical RMM) and web shells, then used Group Policy Objects to push BitLocker activation and encryption tasks across domain-joined systems. Both incidents delivered ransom notes through victims' office printers. Kaspersky notes similarities in the ransom-note wording and delivery method that may link the two cases but states the notes "do not reveal a clear connection between the actors" — so treat them as a shared technique cluster, with "XEntry Team" naming the Mexico intrusion specifically. Kaspersky places the approach in the ShrinkLocker BitLocker-abuse lineage, driven here by an RDP or MSSQL foothold and, in the branded case, an RMM-and-GPO admin workflow rather than a self-contained binary.
The attackers exploited an internet-exposed RDP service on a machine connected to an 8 TB storage device containing mission-critical data.
Finally, in mid-May, the attackers managed to execute a Group Policy Object (GPO) used to deploy activation and encryption tasks, as well as other policies responsible for continued deployment of RMM applications via scheduled tasks.
Although the ransom notes do not reveal a clear connection between the actors, certain words used in the messages, as well as the method of delivery and communication, may confirm a link