XEntry Team is a threat actor associated with BitLocker-based extortion intrusions in Latin America, including confirmed activity affecting organizations in Mexico and likely linked activity in Colombia. Rather than deploying a conventional ransomware family, the actor has been observed abusing legitimate Microsoft functionality and administrative tooling to encrypt systems and pressure victims into paying ransom. A distinctive victim-facing artifact is a blue-screen message claiming systems were "Hacked by XEntry Team," accompanied by printed ransom notes delivered through corporate printers. Observed operations show opportunistic intrusion through exposed and misconfigured services. In Mexico, the actor gained initial access through a misconfigured internet-facing Microsoft SQL Server instance with operating-system command execution enabled, after obtaining credentials from publicly exposed code. The actor then expanded access internally, lowered web-server security settings, attempted web-shell deployment, and used remote monitoring and management software including ManageEngine Endpoint Central, Mesh Agent, and Tactical RMM to maintain access and execute commands. The actor later used scheduled tasks and malicious Group Policy deployment to enable BitLocker at scale across domain-connected systems, including critical infrastructure within the victim environment, and collected recovery material needed to manage the encryption process. A related intrusion in Colombia involved compromise through an exposed RDP service, followed by credential manipulation and selective BitLocker encryption of a drive containing financial data. Similarities in extortion workflow, BitLocker abuse, and ransom-note delivery suggest a possible connection between the Colombia and Mexico incidents. Across these operations, XEntry Team demonstrated capability in initial access, persistence, internal expansion, post-exploitation, defense evasion through living-off-the-land techniques, and data-environment disruption for financial extortion. The actor’s tradecraft reflects abuse of native enterprise administration features and weak security configuration rather than reliance on custom malware families.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducted BitLocker-based extortion in Mexico after exploiting a misconfigured internet-exposed MSSQL service, using xp_cmdshell for command execution, web shells, RMM tools, scheduled tasks, GPO deployment, and printer-delivered ransom notes.
Ransom-motivated intrusion in Mexico involving exploitation of a misconfigured internet-exposed MSSQL service, use of stolen database credentials from code published on GitHub, deployment of RMM tools for persistence and command execution, abuse of GPO and BitLocker to encrypt systems, and printing ransom notes via corporate printers.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.