CTIPilot
← Back to Daily brief 2026-07-22
NOTABLENATOB2threat

Kaspersky documents living-off-the-land BitLocker extortion across two Latin America incidents; the second self-identifies as 'XEntry Team'

BitLocker-for-impact extortion via exposed RDP, MSSQL and RMM/GPO; no encryptor ships, and one crew brands itself 'XEntry Team'

Analysis

Kaspersky's GERT incident-response team documented two 2026 extortion incidents in Latin America that abuse native Windows BitLocker for encryption-for-impact rather than deploying a conventional ransomware family; a living-off-the-land model that leaves no bespoke encryptor for signature-based detection (Kaspersky, 2026-07-21). In the first case (Colombia, June), initial access was an internet-exposed RDP service on a host attached to an 8 TB store of mission-critical data; after manipulating credentials the attacker enabled BitLocker on the drive and demanded roughly USD 3,000. In the second case (Mexico, May) (whose victims' screens displayed "Hacked by XEntry Team") initial access was a misconfigured Microsoft SQL Server whose xp_cmdshell extended stored procedure allowed OS command execution; the operators established persistence through legitimate RMM suites (ManageEngine Endpoint Central, Mesh Agent, Tactical RMM) and web shells, then used Group Policy Objects to push BitLocker activation and encryption tasks across domain-joined systems. Both incidents delivered ransom notes through victims' office printers. Kaspersky notes similarities in the ransom-note wording and delivery method that may link the two cases but states the notes "do not reveal a clear connection between the actors", so treat them as a shared technique cluster, with "XEntry Team" naming the Mexico intrusion specifically. Kaspersky places the approach in the ShrinkLocker BitLocker-abuse lineage, driven here by an RDP or MSSQL foothold and, in the branded case, an RMM-and-GPO admin workflow rather than a self-contained binary.

Cited evidence

The attackers exploited an internet-exposed RDP service on a machine connected to an 8 TB storage device containing mission-critical data.

Finally, in mid-May, the attackers managed to execute a Group Policy Object (GPO) used to deploy activation and encryption tasks, as well as other policies responsible for continued deployment of RMM applications via scheduled tasks.

Although the ransom notes do not reveal a clear connection between the actors, certain words used in the messages, as well as the method of delivery and communication, may confirm a link

Kaspersky (Securelist / GERT) 2026-07-21

Sources1

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.