BitLocker Takes Companies Hostage

Can you imagine arriving at work and being unable to open a single company file?
That is what companies in Colombia and Mexico experienced this year.
It was not a classic ransomware attack or a sophisticated group with custom tools. The attackers used a feature already installed on Windows to encrypt data and demand a ransom.
And when they were done, they did not send a threatening email or display a pop-up message on screen. They printed the extortion notes directly from the office printers.

The attack began long before anyone noticed.
In the case of Mexico, the attackers gained entry through a misconfigured database service whose credentials had been accidentally published on GitHub. From that initial access, they spent three months silently exploring the network, lowering the web server’s security settings, and creating malicious files. Alerts were triggered, but no one investigated them. By the time May arrived, the attackers already controlled the entire infrastructure.
They then deployed legitimate remote management tools.
They installed ManageEngine Endpoint Central, Mesh Agent, and Tactical RMM to remotely manage devices. Using these tools, they scheduled automated tasks that activated BitLocker on every machine in the domain. Each disk received a unique key. Employees were greeted with a blue screen displaying the message Hacked by XEntry Team, and their passwords stopped working. Hours later, the printers spat out ransom notes.
In Colombia, the demand was just $3,000 for critical data.

A small ransom, an enormous amount of damage.
A low ransom does not mean the damage is any less severe. The Colombian company restored the system before forensic investigators could act, destroying all the evidence. The real damage goes far beyond the money.
This method is becoming a trend.
Researchers note that this is not the first time they have seen attackers use BitLocker as a weapon. A few years ago they identified ShrinkLocker using the same approach. The logic is straightforward: using tools built into the operating system avoids triggering antivirus alerts and eliminates the need to purchase ransomware from criminal groups. It is cheaper, quieter, and, as these cases demonstrate, just as effective.

An endpoint without active protection is the perfect entry point.
In Colombia, the targeted system had its EPP disabled due to incompatibilities with other applications. This allowed the attackers to move freely and execute code without any central system raising a flag. A single unprotected device can compromise the entire network.
The logs existed, but no one was looking at them.
In Mexico, EPP alerts fired when the attackers tampered with the web server. The problem was not the technology — it was that no one investigated those warnings. Centralizing logs and responding in a timely manner is the difference between stopping an attack and discovering it only after it is too late.
The printers delivered the final message.
The fact that the attackers used the company’s own printers to deliver their ransom note speaks volumes: they already had total control. And that happened because the doors had been left open for months.
Three urgent steps
- ✓Protect any exposed RDP or MSSQL services with strong authentication.
- ✓Keep the EPP active and investigate every alert without exception.
- ✓Maintain offline backups and verify that you can restore them.
How many devices in your company have the EPP disabled today without anyone knowing?
Security is not improvised, it is audited. At Nacata Security we detect vulnerabilities and protect your company, because a single flaw can cost you everything you have built.
Related articles
Nacata Security, reach out to us anytime
We are Nacata Security, get to know us
web: nacata.io
email: info@nacata.io
Phone: 919930793
LinkedIn: Nacata Security
The ecosystem of malicious actors and the intelligence gathered about them: APT groups and their attribution, ransomware gangs, law enforcement operations and arrests, dark web markets, threat intelligence reports and the geopolitical backdrop of cybercrime.
RATING
9.2
Who are we?
At Nacata Security we are an offensive cybersecurity company specialized in audits and penetration testing.
We detect, assess and help mitigate the vulnerabilities of your systems, networks and applications before a real attacker exploits them, offering 360º defense tailored to each client.
We’d be glad to get in touch with you for whatever you need.




