2026-07-22 · view entry permalink →
Kaspersky documents living-off-the-land BitLocker extortion across two Latin America incidents; the second self-identifies as 'XEntry Team'
Kaspersky's GERT incident-response team documented two 2026 extortion incidents in Latin America that abuse native Windows BitLocker for encryption-for-impact rather than deploying a conventional ransomware family; a living-off-the-land model that leaves no bespoke encryptor for signature-based detection (Kaspersky, 2026-07-21). In the first case (Colombia, June), initial access was an internet-exposed RDP service on a host attached to an 8 TB store of mission-critical data; after manipulating credentials the attacker enabled BitLocker on the drive and demanded roughly USD 3,000. In the second case (Mexico, May) (whose victims' screens displayed "Hacked by XEntry Team") initial access was a misconfigured Microsoft SQL Server whose xp_cmdshell extended stored procedure allowed OS command execution; the operators established persistence through legitimate RMM suites (ManageEngine Endpoint Central, Mesh Agent, Tactical RMM) and web shells, then used Group Policy Objects to push BitLocker activation and encryption tasks across domain-joined systems. Both incidents delivered ransom notes through victims' office printers. Kaspersky notes similarities in the ransom-note wording and delivery method that may link the two cases but states the notes "do not reveal a clear connection between the actors", so treat them as a shared technique cluster, with "XEntry Team" naming the Mexico intrusion specifically. Kaspersky places the approach in the ShrinkLocker BitLocker-abuse lineage, driven here by an RDP or MSSQL foothold and, in the branded case, an RMM-and-GPO admin workflow rather than a self-contained binary.
The attackers exploited an internet-exposed RDP service on a machine connected to an 8 TB storage device containing mission-critical data.
Finally, in mid-May, the attackers managed to execute a Group Policy Object (GPO) used to deploy activation and encryption tasks, as well as other policies responsible for continued deployment of RMM applications via scheduled tasks.
Although the ransom notes do not reveal a clear connection between the actors, certain words used in the messages, as well as the method of delivery and communication, may confirm a link