Securelist
Read post

New BitLocker extortion activity: RDP, MSSQL, RMM Abuse

Kaspersky researchers investigated two BitLocker-based extortion incidents in Latin America — one in Colombia exploiting an exposed RDP service, another in Mexico via a misconfigured MSSQL server with credentials leaked on GitHub. In the Mexico case, attackers operated undetected for three months, deployed multiple RMM tools (ManageEngine Endpoint Central, Mesh Agent, Tactical RMM), used xp_cmdshell for OS-level command execution, and ultimately pushed GPO-based BitLocker encryption across the entire domain. Both attacks used office printers to deliver ransom notes and demanded relatively small sums. Key takeaways include the danger of exposed RDP/MSSQL services, disabled endpoint protection, ignored security alerts, and the growing trend of abusing built-in Windows tools instead of traditional ransomware payloads.

    #ransomware
Jul 21•7m read time•From securelist.com
Post cover image
Table of contents
Initial sign of an attackFirst case: abusing RDP to encrypt dataSecond case: meet the XEntry TeamConclusionsDetection signatures
14 Impressions
Securelist's image
Securelist

Securelist is a cybersecurity blog and research platform operated by Kaspersky Lab. It offers insigh...

74 Followers

•

164 Upvotes

Would you recommend this post?

Copy link
WhatsApp
Facebook
X
New Squad
  • © 2026 Daily Dev Ltd.
  • Guidelines
  • Explore
  • Tags
  • Sources
  • Squads
  • Leaderboard