securelist · Crawled Jul 31, 2026

A new extortion cocktail: office printers, small ransoms, and BitLocker

1 IoCs 1 Malware
Read original article ↗

AI Summary

Two ransomware incidents in Colombia and Mexico involved attackers exploiting misconfigured RDP and MSSQL services to deploy BitLocker for data encryption and extortion. In the first case, attackers accessed an internet-facing RDP service, encrypted a critical 8TB drive, and printed ransom notes via corporate printers, demanding $3,000. In the second case, the 'XEntry Team' exploited a misconfigured MSSQL server with xp_cmdshell enabled, gained OS-level command execution, deployed RMM tools (including Mesh Agent and Tactical RMM), and used Group Policy Objects to mass-deploy BitLocker encryption across domain-joined systems. Victims were notified via blue screen messages and printed ransom notes. Both attacks leveraged built-in Windows tools to avoid reliance on traditional ransomware, indicating a shift toward low-cost, high-impact extortion using native encryption and remote management utilities.

AI-extracted · verify before operational use

Extracted Entities 1 found

Indicators of Compromise 1 extracted

Type Value Detail
Filename web shell files Details →

MITRE ATT&CK TTPs 27 techniques