Ransomware Attacks Using Corporate Printers Found in LATAM

Ransomware Attacks Using Corporate Printers Found in LATAM

Ransomware Attacks Using Corporate Printers Found in LATAM

Kaspersky has disclosed details of two ransomware incidents in Latin America in which attackers combined the use of Microsoft’s BitLocker encryption tool with an unusual tactic: hijacking corporate printers to distribute ransom notes throughout affected organizations.

Ransomware Attacks Using Corporate Printers Found in LATAM

The incidents, investigated by Kaspersky Security Services between May and June 2026, targeted organizations in Colombia and Mexico. According to the company, the attacks relied primarily on exposed internet-facing services, security misconfigurations, and legitimate administrative tools rather than custom-built malware.

In the Colombian case, attackers reportedly gained access through an internet-exposed remote access service connected to a server managing an 8 TB storage device containing business-critical data. After taking control of the environment and modifying user credentials, they used BitLocker to encrypt a storage volume that primarily contained financial information, rendering the data inaccessible. The attackers then used the organization’s network printers to print ransom notes demanding payment.

A separate investigation in Mexico found that a group identifying itself as the “XEntry Team” allegedly accessed an organization’s network through a misconfigured Microsoft SQL Server after obtaining login credentials exposed in publicly available source code. Kaspersky said the attackers expanded beyond the database environment, weakened web server protections, and maintained persistent access for several months before the intrusion was discovered. Employees eventually became aware of the compromise when their computers displayed a message reading “Hacked by XEntry Team,” and their usual login credentials no longer worked.

In both incidents, users first noticed that their systems had been encrypted when padlock icons appeared next to drives in Windows Explorer, indicating that BitLocker had been activated and access to stored data had been restricted.

According to Kaspersky, the use of corporate printers to distribute ransom demands is an uncommon technique that may be intended to increase the visibility of the attack and apply additional psychological pressure on victims. However, the company noted that while the ransom notes shared similarities in wording, delivery method, and communication style, the available evidence does not conclusively show that the same threat actor was responsible for both incidents.


Related:

Comment:

Please leave your comment below about the news: Ransomware Attacks Using Corporate Printers Found in LATAM.

0 replies

Leave a Comment

Want to join the discussion?
Feel free to contribute!

Leave a Reply

Your email address will not be published. Required fields are marked *