- Kaspersky detailed ransomware cases in Colombia and Mexico where attackers exploited misconfigured systems
- Victims’ drives were locked with BitLocker, ransom notes printed via office printers
- New group “XEntry Team” claimed responsibility; misconfigurations remain a major breach risk
Cybercriminals have, in true Hollywood fashion, started using office printers to notify victims they were struck by ransomware.
Security researchers at Kaspersky have detailed two incidents which recently took place, one in Colombia, and one in Mexico, where cybercriminals took advantage of misconfigured systems.
However both had the same outcome - the attackers used BitLocker to lock down key drives, and then used office printers to print out their ransom notes.
Latest Videos From
XEntry Team claims the attacks
In Colombia, a machine containing eight terabytes of mission-critical data had its Endpoint Protection Platform (EPP) disabled due to compatibility issues. It also had an internet-exposed Remote Desktop Protocol (RDP) running, which enabled relatively easy access for the attackers.
The Mexico attack was somewhat different. Three months before springing to action, the attackers discovered misconfigurations in the MSSQL service which granted them privileged access to the target environment. They spent the next couple of months lowering the server’s security settings, dropping web shells, and even though some triggered EPP alarms, the victims never investigated thoroughly.
In the Colombia case, the attackers asked for only $3,000, an offer the victims quickly accepted. Therefore, there was not enough forensic evidence left behind to conduct a thorough investigation. Kaspersky did not say how much money the attackers asked for in the Mexico case, or if the victims ended up paying or not.
In both cases, the attackers did not exploit a vulnerability, or even target an oblivious employee with social engineering. Instead, they exploited misconfigurations, which continue to be one of the biggest causes of breaches and data leaks.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
“We strongly recommend configuring the RDP in strict accordance with cybersecurity best practices to prevent unauthorized access,” Kaspersky warned. “This is especially critical: according to our Global Report: Anatomy of a Cyber World, more than 13% of incidents are related to policy violations and configuration errors, confirming that misconfigurations continue to pose a significant risk.”
The attacks were done by a group calling itself “XEntry Team”. There are no prior reports of this group, and it is either a previously unknown threat actor, or a simple rebrand.
The best antivirus for all budgets
Our top picks, based on real-world testing and comparisons
Follow TechRadar on Google News andadd us as a preferred source to get our expert news, reviews, and opinion in your feeds.