Kaspersky reports of ransomware attacks against organizations in Mexico and Colombia in which attackers encrypted systems with BitLocker and used compromised corporate printers to deliver ransom notes, highlighting a growing reliance on misconfigured infrastructure and legitimate administrative tools rather than sophisticated malware.
Ransomware operators are adopting increasingly unconventional tactics to intensify pressure on victims. According to new research from Kaspersky, attacks targeting organizations in Mexico and Colombia found that cybercriminals not only encrypted systems using Microsoft’s BitLocker encryption tool but also hijacked corporate printers to physically distribute ransom demands throughout affected organizations.
The incidents, investigated by Kaspersky Security Services between May and June 2026, illustrate how attackers are increasingly exploiting exposed internet-facing services, misconfigured infrastructure, and legitimate administrative tools already present within enterprise environments instead of relying solely on custom malware.
“These incidents reflect an increasingly practical trend in ransomware attacks,” says Eduardo Chavarro, Director of the Global Incident Response Team for the Americas, Kaspersky. “Instead of relying on sophisticated malware, cybercriminals are exploiting internet-exposed services, poor configurations and legitimate administrative tools that already exist within organizations to encrypt information and pressure victims into paying a ransom. In some cases, they even use methods such as printing ransom notes to increase psychological pressure and reinforce the urgency of their demands.”
The findings reinforce the importance of securing enterprise configurations and continuously monitoring networks for signs of unauthorized access.
Legitimate Tools Become Ransomware Weapons
In each incident, the first indication for employees was that their systems had been encrypted with BitLocker, a legitimate Windows encryption feature. Users noticed lock icons appearing next to their drives in Windows File Explorer, signaling that corporate data had become inaccessible.
One of the attacks targeted an organization in Colombia through an internet-exposed remote access service connected to a server managing an 8TB storage device containing business-critical information. After gaining control of the environment and modifying user credentials, the attackers encrypted the storage system, which primarily contained financial data.
Once the encryption process was complete, the attackers leveraged the organization’s own network printers to print ransom notes demanding payment in exchange for restoring access to the encrypted information. According to Kaspersky, using compromised corporate printers represents an unusual tactic designed to reinforce the visibility of the attack and increase pressure on victims by making the ransom demand unavoidable across the organization.
Misconfigurations Create Entry Points
A separate incident in Mexico revealed a different initial access vector but a similar operational approach. Kaspersky identified a threat group calling itself XEntry Team that gained access through a misconfigured Microsoft SQL Server after obtaining exposed credentials embedded in publicly available code. From there, the attackers expanded beyond the database environment, disabled security protections on the organization’s web server, and maintained persistent access to the infrastructure for several months before the compromise was discovered.
Employees became aware of the incident when their computers displayed a blue screen carrying the message “Hacked by XEntry Team,” while their standard credentials no longer allowed them to log into corporate systems.
Although Kaspersky says the ransom notes analyzed do not conclusively prove that both incidents were carried out by the same threat actor, similarities in language, delivery methods, and communication style suggest the attacks could be related. The investigations also demonstrate that weak configurations remain one of the most common pathways for ransomware operators seeking initial access into enterprise networks.
Strengthening Defenses Against Evolving Attacks
Kaspersky says organizations should strengthen defensive measures by securing exposed Remote Desktop Protocol services, centralizing, and protecting security logs, continuously monitoring alerts and immediately investigating signs of unauthorized access.
The company also recommends implementing strict application control policies and actively monitoring network traffic for command-and-control communications. According to Kaspersky’s Global Report: Anatomy of a Cyber World, more than 13% of security incidents are associated with policy violations and configuration errors, while more than 20% involve the misuse of Remote Monitoring and Management tools for attack execution and command-and-control activity.
The researchers note that attackers increasingly combine multiple legitimate administrative tools within a single intrusion, making behavioral monitoring and rapid incident response as important as traditional malware detection.
Click Here For The Original Source.
