ctipilot.ch

XEntry Team

actor · actor:xentry-team single-source

Financially-motivated BitLocker-abuse extortion actor named from a May 2026 Mexico incident whose victims' screens displayed 'Hacked by XEntry Team' (Kaspersky GERT, 2026-07-21): initial access via a misconfigured Microsoft SQL Server (xp_cmdshell), persistence via legitimate RMM tools (ManageEngine Endpoint Central, Mesh Agent, Tactical RMM) and web shells, BitLocker deployed via GPO for encryption-for-impact, small ransom (~USD 3,000), ransom notes printed on office printers. Kaspersky documented a separate June 2026 Colombia BitLocker-extortion case (RDP-based) with which it assesses a POSSIBLE but unconfirmed link (ransom-note wording/delivery similarities; 'do not reveal a clear connection between the actors'). ShrinkLocker BitLocker-abuse lineage.

Coverage timeline
1
first 2026-07-22 → last 2026-07-22
Peak priority
notable
1 notable
Sources cited
1
1 hosts
Sections touched
1
active-threats
Co-occurring entities
0
no co-occurrence
ATT&CK techniques
6
pinned v19.1 · see below

Hunting pivots

Affected products
ManageEngine Endpoint CentralMicrosoft SQL ServerMicrosoft Windows BitLockerTactical RMM

ATT&CK techniques

6 techniques observed across 1 entry — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.1 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1133External Remote Services×1

Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect to internal enterprise network resources from external locations. There are often remote service gateways that manage connections and credential authentication for these services. Services such as Windows Remote Management and VNC can also be used externally.

Evidence: 2026-07-22/xentry-team-bitlocker-lotl-extortion-rmm-gpo · ATT&CK page ↗

Persistence TA0003

T1133External Remote Services×1

Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect to internal enterprise network resources from external locations. There are often remote service gateways that manage connections and credential authentication for these services. Services such as Windows Remote Management and VNC can also be used externally.

Evidence: 2026-07-22/xentry-team-bitlocker-lotl-extortion-rmm-gpo · ATT&CK page ↗

T1505.001Server Software Component: SQL Stored Procedures×1

Adversaries may abuse SQL stored procedures to establish persistent access to systems. SQL Stored Procedures are code that can be saved and reused so that database users do not waste time rewriting frequently used SQL queries. Stored procedures can be invoked via SQL statements to the database using the procedure name or via defined events (e.g. when a SQL server application is started/restarted).

Evidence: 2026-07-22/xentry-team-bitlocker-lotl-extortion-rmm-gpo · ATT&CK page ↗

T1505.003Server Software Component: Web Shell×1

Adversaries may backdoor web servers with web shells to establish persistent access to systems. A Web shell is a Web script that is placed on an openly accessible Web server to allow an adversary to access the Web server as a gateway into a network. A Web shell may provide a set of functions to execute or a command-line interface on the system that hosts the Web server.

Evidence: 2026-07-22/xentry-team-bitlocker-lotl-extortion-rmm-gpo · ATT&CK page ↗

Privilege Escalation TA0004

T1484.001Domain or Tenant Policy Modification: Group Policy Modification×1

Adversaries may modify Group Policy Objects (GPOs) to subvert the intended discretionary access controls for a domain, usually with the intention of escalating privileges on the domain. Group policy allows for centralized management of user and computer settings in Active Directory (AD). GPOs are containers for group policy settings made up of files stored within a predictable network path `\<DOMAIN>\SYSVOL\<DOMAIN>\Policies\`.

Evidence: 2026-07-22/xentry-team-bitlocker-lotl-extortion-rmm-gpo · ATT&CK page ↗

Defense Impairment TA0112

T1484.001Domain or Tenant Policy Modification: Group Policy Modification×1

Adversaries may modify Group Policy Objects (GPOs) to subvert the intended discretionary access controls for a domain, usually with the intention of escalating privileges on the domain. Group policy allows for centralized management of user and computer settings in Active Directory (AD). GPOs are containers for group policy settings made up of files stored within a predictable network path `\<DOMAIN>\SYSVOL\<DOMAIN>\Policies\`.

Evidence: 2026-07-22/xentry-team-bitlocker-lotl-extortion-rmm-gpo · ATT&CK page ↗

Command and Control TA0011

T1219Remote Access Tools×1

An adversary may use legitimate remote access tools to establish an interactive command and control channel within a network. Remote access tools create a session between two trusted hosts through a graphical interface, a command line interaction, a protocol tunnel via development or management software, or hardware-level access such as KVM (Keyboard, Video, Mouse) over IP solutions. Desktop support software (usually graphical interface) and remote management software (typically command line interface) allow a user to control a computer remotely as if they are a local user inheriting the user or software permissions. This software is commonly used for troubleshooting, software installation, and system management. Adversaries may similarly abuse response features included in EDR and other defensive tools that enable remote access.

Evidence: 2026-07-22/xentry-team-bitlocker-lotl-extortion-rmm-gpo · ATT&CK page ↗

Impact TA0040

T1486Data Encrypted for Impact×1

Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources. They can attempt to render stored data inaccessible by encrypting files or data on local and remote drives and withholding access to a decryption key. This may be done in order to extract monetary compensation from a victim in exchange for decryption or a decryption key (ransomware) or to render data permanently inaccessible in cases where the key is not saved or transmitted.

Evidence: 2026-07-22/xentry-team-bitlocker-lotl-extortion-rmm-gpo · ATT&CK page ↗

Story timeline

  1. 2026-07-22Kaspersky documents living-off-the-land BitLocker extortion across two Latin America incidents; the second self-identifies as 'XEntry Team'
    active-threatsBitLocker-for-impact extortion via exposed RDP, MSSQL and RMM/GPO — no encryptor ships, and one crew brands itself 'XEntry Team'

Where this entity is cited

  • active-threats1

Source distribution

  • securelist.com1 (100%)

explore in graph

Entries about XEntry Team (1)

2026-07-22 · view entry permalink →

NOTABLENATOB2

Kaspersky documents living-off-the-land BitLocker extortion across two Latin America incidents; the second self-identifies as 'XEntry Team'

Kaspersky's GERT incident-response team documented two 2026 extortion incidents in Latin America that abuse native Windows BitLocker for encryption-for-impact rather than deploying a conventional ransomware family — a living-off-the-land model that leaves no bespoke encryptor for signature-based detection (Kaspersky, 2026-07-21). In the first case (Colombia, June), initial access was an internet-exposed RDP service on a host attached to an 8 TB store of mission-critical data; after manipulating credentials the attacker enabled BitLocker on the drive and demanded roughly USD 3,000. In the second case (Mexico, May) — whose victims' screens displayed "Hacked by XEntry Team" — initial access was a misconfigured Microsoft SQL Server whose xp_cmdshell extended stored procedure allowed OS command execution; the operators established persistence through legitimate RMM suites (ManageEngine Endpoint Central, Mesh Agent, Tactical RMM) and web shells, then used Group Policy Objects to push BitLocker activation and encryption tasks across domain-joined systems. Both incidents delivered ransom notes through victims' office printers. Kaspersky notes similarities in the ransom-note wording and delivery method that may link the two cases but states the notes "do not reveal a clear connection between the actors" — so treat them as a shared technique cluster, with "XEntry Team" naming the Mexico intrusion specifically. Kaspersky places the approach in the ShrinkLocker BitLocker-abuse lineage, driven here by an RDP or MSSQL foothold and, in the branded case, an RMM-and-GPO admin workflow rather than a self-contained binary.

The attackers exploited an internet-exposed RDP service on a machine connected to an 8 TB storage device containing mission-critical data.

Finally, in mid-May, the attackers managed to execute a Group Policy Object (GPO) used to deploy activation and encryption tasks, as well as other policies responsible for continued deployment of RMM applications via scheduled tasks.

Although the ransom notes do not reveal a clear connection between the actors, certain words used in the messages, as well as the method of delivery and communication, may confirm a link

Kaspersky (Securelist / GERT) 2026-07-21
threat22 Jul 04:34Zsingle-sourceOpen finding ↗