Attackers carried out two extortion intrusions in Latin America by abusing exposed Microsoft services and legitimate administration tools rather than deploying conventional ransomware. In one case in Colombia, a threat actor accessed an internet-facing RDP service, seized control of a system connected to an 8 TB storage device, encrypted the financial-data drive with BitLocker, and printed ransom notes demanding $3,000. In another case in Mexico, the group identified as XEntry Team exploited a misconfigured internet-facing Microsoft SQL Server with xp_cmdshell enabled after obtaining database credentials from code exposed on GitHub.
After gaining access in Mexico, the attackers expanded through the environment by weakening web server security settings, deploying web shells, and installing remote management tools including ManageEngine Endpoint Central, Mesh Agent, and Tactical RMM for persistence and command execution. They then used Group Policy Objects and scheduled tasks to enable BitLocker and encrypt disks across the domain, while victims reported blue screens reading "Hacked by XEntry Team," failed credentials, locked drives, and ransom notes printed from corporate printers. The incidents highlighted how exposed services, poor credential hygiene, weak alert handling, and ineffective endpoint protection can turn built-in Windows functionality into an enterprise-wide extortion mechanism.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
In the June 2021 Colombia incident, the attackers printed ransom notes demanding $3,000 after encrypting the victim's financial-data drive with BitLocker. The activity was part of a ransomware-style extortion scheme abusing legitimate Microsoft functionality.
In June 2021, attackers exploited an internet-exposed RDP service at a company in Colombia and took control of a machine connected to an 8 TB storage device. They encrypted the financial-data drive with BitLocker as part of an extortion attempt.
During the May 2021 Mexico intrusion, the attackers used GPO and scheduled tasks to enable BitLocker and encrypt disks across the domain. Victims observed locked drives, blue screens reading "Hacked by XEntry Team," failed credentials, and ransom notes printed from corporate printers.
In May 2021, attackers identified as XEntry Team exploited a misconfigured internet-facing Microsoft SQL Server with xp_cmdshell enabled after obtaining database credentials from code exposed on GitHub. They expanded access internally, lowered web server security settings, created web shells, and deployed remote management tools for persistence and command execution.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.