Ransomware Exploits Windows BitLocker to Encrypt Data, Even Prints Ransom Notes on Office Printers — BigGo Finance | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


Ransomware attacks that hold corporate data hostage for money are becoming increasingly sophisticated. Security researchers have now identified cases where attackers, instead of distributing custom malware, are exploiting the legitimate disk encryption feature built into the Microsoft Windows operating system to lock up files. A new tactic has also emerged: printing ransom notes directly on the victim company’s office printers to apply psychological pressure.

Global cybersecurity firm Kaspersky announced on the 6th that its analysis of a series of ransomware attacks targeting companies in Colombia and Mexico between May and June confirmed that the attackers exploited Windows’ disk encryption feature, BitLocker.

BitLocker is a legitimate security feature used in enterprise environments to prevent data leaks. However, in these incidents, the attackers infiltrated the systems and then activated BitLocker to encrypt critical data themselves. Employees at the victim companies only realized they were under attack when they saw a lock icon next to their drives in Windows Explorer and found they could no longer access their files.

According to Kaspersky’s investigation, the attack in Colombia originated from a remote access service that was left exposed to the internet without protection. This service was configured on a server connected to an 8-terabyte storage device holding the company’s core data. After gaining control of the system, the attacker changed user account credentials and encrypted the drive containing financial data using BitLocker. In a calculated move, the attacker then printed and distributed a ransom note via the company’s printers.

A separate incident detected in Mexico was carried out by attackers identifying themselves as the “XEntry Team.” They obtained login credentials accidentally exposed in publicly available source code and initially breached the corporate internal network through a Microsoft SQL server with weak security settings. They subsequently weakened the web server’s security configuration and maintained access to the internal infrastructure for months, operating covertly. This attack was discovered when employees’ PC screens turned into a blue screen displaying the message “Hacked by XEntry Team,” and they could no longer log into the system with their existing accounts.

“These cases demonstrate that recent ransomware attacks do not necessarily rely on sophisticated malware,” said Eduardo Chavarro Ovalle, Manager of Kaspersky’s Digital Forensics and Incident Response Group. “Attackers are exploiting internet-exposed services, system misconfigurations, and legitimate administrative tools already present in corporate environments to encrypt data and pressure victim organizations into paying ransoms.” He added, “In some instances, they even utilized the method of printing ransom notes on printers to exert psychological pressure on victims and further highlight the urgency of their demands.”

To defend against such attacks, Manager Ovalle stressed the need to “manage logs centrally and securely, continuously monitor security alerts, and promptly investigate signs of unauthorized access.”

Lee Hyo-eun, General Manager of Kaspersky Korea, noted, “South Korean companies, with their high level of digital transformation, are continuously exposed to ransomware threats.” She pointed out that “recent attackers are not only exploiting vulnerabilities in existing corporate systems and configurations but are also combining psychological pressure techniques to increase the likelihood of a successful attack.”

GM Lee urged companies to shift from a post-incident response approach to a prevention-focused security strategy. “Organizations must regularly inspect system vulnerabilities and configuration errors, continuously monitor for unauthorized access, and establish a system capable of early threat detection and response,” she stated. “This proactive approach will be a core competitive advantage in protecting business continuity and critical assets from increasingly sophisticated ransomware attacks.”

To mitigate the damage from such ransomware attacks, Kaspersky recommended key security measures for enterprises, including: deploying integrated security platforms such as Endpoint Detection and Response (EDR) and Extended Detection and Response (XDR); utilizing Managed Detection and Response (MDR) and Incident Response (IR) services; strengthening security settings for Remote Desktop Protocol (RDP); and establishing a multi-layered security architecture that includes application control and Command and Control (C2) communication monitoring.

——————————————————–


Click Here For The Original Source.

.........................

National Cyber Security

FREE
VIEW