A new extortion cocktail: office printers, small ransoms, and BitLocker
AI Summary
Two ransomware incidents in Colombia and Mexico involved attackers exploiting misconfigured RDP and MSSQL services to deploy BitLocker for data encryption and extortion. In the first case, attackers accessed an internet-facing RDP service, encrypted a critical 8TB drive, and printed ransom notes via corporate printers, demanding $3,000. In the second case, the 'XEntry Team' exploited a misconfigured MSSQL server with xp_cmdshell enabled, gained OS-level command execution, deployed RMM tools (including Mesh Agent and Tactical RMM), and used Group Policy Objects to mass-deploy BitLocker encryption across domain-joined systems. Victims were notified via blue screen messages and printed ransom notes. Both attacks leveraged built-in Windows tools to avoid reliance on traditional ransomware, indicating a shift toward low-cost, high-impact extortion using native encryption and remote management utilities.
AI-extracted · verify before operational use
Extracted Entities 1 found
Indicators of Compromise 1 extracted
| Type | Value | Detail |
|---|---|---|
| Filename | web shell files | Details → |