XEntry Team is a threat actor associated with BitLocker-based extortion intrusions in Latin America, including reported activity affecting organizations in Mexico and Colombia. The actor appears to favor living-off-the-land and dual-use administration approaches over deployment of a conventional ransomware family, abusing legitimate Microsoft functionality and remote management tooling to encrypt systems, disrupt operations, and coerce payment. Observed tradecraft includes exploitation of exposed remote access and misconfigured enterprise services for initial access, notably internet-facing RDP and Microsoft SQL Server instances with unsafe command-execution features enabled. In at least one intrusion, access was facilitated by exposed credentials in publicly accessible code repositories. After establishing a foothold, the actor expanded laterally into internal systems, attempted web-shell deployment, reduced security settings on exposed servers, and used remote monitoring and management software for persistence, command execution, and broad operational reach. A defining characteristic of XEntry Team activity is the abuse of BitLocker to encrypt victim systems and data volumes. The actor has used scheduled tasks and Group Policy-based deployment to enable encryption across domain-connected assets, including prioritization of critical systems before wider propagation. Victims have reported loss of credential access, system lockouts, and ransom-note delivery through corporate printers, along with on-screen defacement referencing XEntry Team. Known tooling and techniques associated with this activity include use of RMM platforms such as ManageEngine Endpoint Central, Mesh Agent, and Tactical RMM; command execution through SQL Server misconfiguration; lateral movement through enterprise administration infrastructure; and reliance on native Windows capabilities for encryption and system control. The activity overlaps operationally with other BitLocker-abuse extortion cases sometimes compared to ShrinkLocker, but attribution beyond the XEntry Team name remains limited. Available reporting indicates the actor has benefited from weak configuration management, exposed services, disabled or poorly monitored endpoint protections, and inadequate incident-response handling at victim organizations. High-confidence characterization supports describing XEntry Team as an extortion-focused intrusion actor using legitimate administrative mechanisms and BitLocker abuse rather than a traditional commodity ransomware deployment model. Publicly available information is currently insufficient to confidently assess a nation-state affiliation.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducted BitLocker-based extortion in Mexico after exploiting a misconfigured internet-exposed MSSQL service, using xp_cmdshell for command execution, web shells, RMM tools, scheduled tasks, GPO deployment, and printer-delivered ransom notes.
Ransom-motivated intrusion in Mexico involving exploitation of a misconfigured internet-exposed MSSQL service, use of stolen database credentials from code published on GitHub, deployment of RMM tools for persistence and command execution, abuse of GPO and BitLocker to encrypt systems, and printing ransom notes via corporate printers.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.