Ransomware Group "XEntry Team" Exploits Misconfigurations in Colombia and Mexico
Security researchers at Kaspersky have uncovered two recent ransomware attacks one in Colombia and another in Mexico where cybercriminals exploited misconfigured systems to deploy BitLocker encryption and print ransom notes via office printers.
In Colombia, attackers targeted a machine holding eight terabytes of critical data after disabling its Endpoint Protection Platform (EPP) due to compatibility issues. The system also had an exposed Remote Desktop Protocol (RDP), allowing easy access. The threat actors demanded $3,000, which the victim paid, leaving insufficient forensic evidence for a full investigation.
In Mexico, the attack unfolded over three months. Attackers first identified misconfigurations in the MSSQL service, gaining privileged access. They then weakened security settings, deployed web shells, and evaded detection despite triggering EPP alerts. The ransom amount and whether the victim paid remain undisclosed.
Both incidents were attributed to a new group called "XEntry Team", which appears to be either a previously unknown threat actor or a rebrand. Unlike traditional ransomware attacks, these breaches did not rely on vulnerabilities or social engineering but instead exploited misconfigurations a leading cause of data breaches.
Kaspersky’s findings highlight the persistent risk of improperly secured systems, with misconfigurations accounting for over 13% of cyber incidents globally. The attacks underscore the need for strict adherence to security best practices, particularly in managing exposed services like RDP.
Kaspersky cybersecurity rating report: https://www.rankiteo.com/company/kaspersky
"id": "KAS1784744898",
"linkid": "kaspersky",
"type": "Ransomware",
"date": "4/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'location': 'Colombia'}, {'location': 'Mexico'}],
'attack_vector': 'Misconfigured systems, exposed RDP, weakened MSSQL service',
'data_breach': {'data_encryption': 'BitLocker encryption',
'sensitivity_of_data': 'Critical data (Colombia incident)'},
'description': 'Security researchers at Kaspersky uncovered two ransomware '
'attacks in Colombia and Mexico where cybercriminals exploited '
'misconfigured systems to deploy BitLocker encryption and '
'print ransom notes via office printers. The attacks were '
"attributed to a new group called 'XEntry Team'.",
'impact': {'data_compromised': '8 terabytes (Colombia incident)',
'financial_loss': '$3,000 (Colombia incident)'},
'initial_access_broker': {'entry_point': 'Exposed RDP (Colombia), '
'misconfigured MSSQL service '
'(Mexico)',
'reconnaissance_period': '3 months (Mexico '
'incident)'},
'investigation_status': 'Partial (Colombia incident due to insufficient '
'forensic evidence)',
'lessons_learned': 'Misconfigurations account for over 13% of cyber incidents '
'globally. Strict adherence to security best practices is '
'necessary, particularly in managing exposed services like '
'RDP.',
'motivation': 'Financial gain',
'post_incident_analysis': {'root_causes': 'Misconfigured systems, exposed '
'RDP, weakened MSSQL service '
'security settings'},
'ransomware': {'data_encryption': 'BitLocker encryption',
'ransom_demanded': '$3,000 (Colombia incident)',
'ransom_paid': 'Yes (Colombia incident)'},
'recommendations': 'Improve system configurations, secure exposed services '
'like RDP, and monitor for misconfigurations.',
'references': [{'source': 'Kaspersky'}],
'response': {'third_party_assistance': 'Kaspersky'},
'threat_actor': 'XEntry Team',
'title': "Ransomware Group 'XEntry Team' Exploits Misconfigurations in "
'Colombia and Mexico',
'type': 'Ransomware',
'vulnerability_exploited': 'Misconfigurations'}