Two recent ransomware cases in Latin America weren’t powered by some custom “homemade crypto” malware. Instead, attackers weaponized what Windows already provides: BitLocker—and used office printers as the final delivery channel. Kaspersky reports incidents in Mexico (May) and Colombia (June). In Colombia, the attackers entered via an internet-exposed Windows RDP server, then expanded access by modifying credentials. Only key volumes (including an 8TB storage device with critical business data) were BitLocker-encrypted for maximum impact. Worse: endpoint protection had been disabled for compatibility, giving attackers a cleaner path to recon. In Mexico, the attackers started with leaked database credentials found on public sources like GitHub, then logged into a misconfigured Microsoft SQL Server. Because the DB could execute Windows commands, they pivoted into the network, lowered web security, and created persistence. Both campaigns later installed legitimate remote admin tools, scheduled BitLocker at scale, harvested recovery keys, then blasted encryption through domain-wide Group Policy. Employees saw the account outage—then the printers started printing ransom notes. #Ransomware #BitLocker #IncidentResponse #SecurityOperations #WindowsSecurity #ZeroTrust
Want to learn more? Visit Explore the world, stay updated on travel insights and international affairs, and discover authentic stories from real life
评论
发表评论