Home / Technology / Printers Deliver Ransom Demands in New Cyberattack
Printers Deliver Ransom Demands in New Cyberattack
22 Jul
Summary
- Attackers used BitLocker to encrypt drives and printed ransom notes.
- New group 'XEntry Team' claimed responsibility for the attacks.
- Misconfigured systems, not exploits, enabled these breaches.

Cybercriminals are now employing office printers to deliver ransomware demands, as detailed by Kaspersky researchers. Two recent incidents, one in Colombia and another in Mexico, involved attackers exploiting misconfigured systems rather than traditional vulnerabilities.
In both cases, victims' drives were encrypted using BitLocker, and ransom notes were printed on office printers. The new group 'XEntry Team' has claimed responsibility for these attacks. In Colombia, attackers gained access through an internet-exposed Remote Desktop Protocol (RDP) and demanded $3,000. The Mexico attack involved attackers discovering and exploiting misconfigurations in an MSSQL service over several months.
Kaspersky stressed that misconfigurations remain a significant risk, with over 13% of incidents attributed to policy violations and configuration errors. They strongly recommend configuring RDP according to cybersecurity best practices to prevent unauthorized access. The XEntry Team is either a new threat actor or a rebranded existing group.