Skip to main content

Prints of darkness: Hackers printing demands during ransomware campaigns across Latin America - Kaspersky

July 21, 2026

The threat actors deployed BitLocker in multiple attacks and used corporate printers to deliver ransom notes directly to affected organizations.

Between May and June 2026, Kaspersky Security Services experts investigated a series of ransomware incidents targeting organizations in Colombia and Mexico. The attacks involved misconfigurations, BitLocker encryption, and the abuse of corporate printers to deliver ransom demands. In the analyzed cases, the attackers informed the targeted organizations that their infrastructure had been compromised and that payment was required to restore access to their data. Affected users first noticed a padlock icon next to their drives in Windows Explorer, indicating that the systems had been encrypted with BitLocker and that the files were no longer accessible.

One of the investigated incidents took place in Colombia, where attackers gained entry through an internet-exposed remote access service linked to a server connected to an 8 TB storage device containing business-critical data. After establishing control of the environment and altering user credentials, the threat actor leveraged BitLocker to encrypt the drive, which primarily stored financial information. The attackers then rendered the data inaccessible and used the organization’s own printers to distribute ransom demands.

Ransomware note distributed by a threat actor during one of the attacksRansomware note distributed by a threat actor during one of the attacks

In a separate incident in Mexico, Kaspersky experts found that attackers calling themselves the “XEntry team” gained initial access through a misconfigured Microsoft SQL server after obtaining login credentials exposed in publicly available code. From there, they moved beyond the database environment, weakened web server protections, and established persistent access across the organization’s infrastructure for several months before the intrusion was detected. The compromise ultimately became visible to employees when their machines displayed a blue screen bearing the message “Hacked by XEntry Team,” while their usual credentials no longer allowed them to access their systems.

“These incidents highlight a pragmatic approach to ransomware,” said Eduardo Chavarro Ovalle, Kaspersky digital forensic and incident response group manager. “Instead of relying on sophisticated malware, attackers are taking advantage of exposed services, weak configurations, and legitimate administrative tools already present in the environment to encrypt data and pressure victims into paying. In some cases, they also use channels such as printed ransom notes to exert psychological pressure on victims and reinforce the urgency of their demands. To defend against this type of intrusion, organizations should centralize and secure logs, closely monitor alerts, and rapidly investigate any signs of unauthorized access.”

Although the ransom notes do not conclusively establish that the same actor was behind these incidents, similarities in wording, delivery method and communication style may indicate a possible connection.

More details available on Securelist.com.

Kaspersky Security Services experts advise that organizations:

  • Implement a reliable solution such as Kaspersky Next which enables unified real-time protection, threat visibility, investigation and the response capabilities of EDR and XDR.

  • Apply such cybersecurity solutions such as Kaspersky Compromise Assessment, Managed Detection and Response and Incident Response which help protect against evasive cyberattacks, investigate incidents and provide additional expertise if companies lack cybersecurity workers.

  • Configure the Remote Desktop Protocol (RDP) in strict accordance with cybersecurity best practices to prevent unauthorized access. This is especially critical given that, according to our Global Report: Anatomy of a Cyber World, more than 13% of incidents are related to policy violations and configuration errors, confirming that such misconfigurations continue to pose a significant risk.

  • Prioritize implementing strict application control policies and actively monitoring network traffic for command-and-control (C2) communications. This is especially critical given that more than 20% of incidents involved the abuse of RMM (Remote Monitoring and Management) tools for execution and C2 strategies. The fact that attackers use more than three distinct tools to gain control in a single incident further underscores the urgent need for these measures. 

Prints of darkness: Hackers printing demands during ransomware campaigns across Latin America - Kaspersky

The threat actors deployed BitLocker in multiple attacks and used corporate printers to deliver ransom notes directly to affected organizations.
Kaspersky logo

About Kaspersky

Kaspersky is a global cybersecurity and digital privacy company founded in 1997. Innovating the industry with a Cyber Immunity approach, Kaspersky safeguards consumers, businesses, critical infrastructure, and governments from cyberthreats, with over a billion devices protected to date.

Kaspersky ensures Cybersecurity True to Business, focusing on providing clear outcomes, protecting revenue, easing workloads and preventing downtime. Kaspersky’s deep threat intelligence and security expertise is constantly transforming into innovative solutions and services for organizations of every size, from small businesses to large enterprises, combining proven AI-driven protection technologies with simple management and expert support.

Recognized in independent tests and trusted by millions of individuals worldwide and nearly 200,000 organizations, Kaspersky helps detect threats earlier, respond faster and operate with greater confidence and freedom, protecting what matters most to our clients. Learn more at www.kaspersky.com.

Related Articles Press Releases