Attackers in Colombia and Mexico encrypted victim systems by abusing BitLocker, turning native Microsoft functionality into a low-cost extortion tool instead of deploying custom ransomware. In the Colombia case, intruders accessed an internet-exposed RDP service, changed user credentials, encrypted a critical 8 TB storage volume holding financial data, and demanded less than $3,000; the victim reportedly paid before forensic evidence could be preserved. Victims were alerted by locked drives, failed logins, and in some cases blue-screen messages reading "Hacked by XEntry Team."
In the Mexico intrusion, attackers exploited a misconfigured internet-facing Microsoft SQL Server using leaked MSSQL credentials exposed in GitHub code, then abused xp_cmdshell, remote monitoring and management tools including ManageEngine Endpoint Central, Mesh Agent, and Tactical RMM, and GPO-based task deployment to spread BitLocker encryption across domain-connected systems. Ransom notes were printed directly from corporate office printers, and researchers said weak configuration management, exposed remote services, poor monitoring of endpoint protections, and misuse of legitimate administration tools enabled both incidents; similarities in ransom-note wording and delivery suggest the operations may be linked, with one case attributed to XEntry Team.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
In a May incident in Mexico, attackers used leaked MSSQL credentials found in code published on GitHub to access a misconfigured internet-exposed Microsoft SQL Server with xp_cmdshell enabled. They then expanded access, attempted web shell creation, used RMM tools, and deployed GPO-based tasks to spread BitLocker encryption across domain-connected systems.
In a June incident in Colombia, attackers accessed an internet-exposed RDP service, changed user credentials, and enabled BitLocker on a critical 8 TB storage volume containing financial data. They demanded a ransom of less than $3,000, which the victim paid before forensic evidence could be preserved.
Kaspersky Securelist published research on ShrinkLocker, describing ransomware abuse of Microsoft BitLocker. This established prior public reporting on BitLocker being turned into a ransomware mechanism.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcesecurelist.ru
Open sourcesecurelist.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.