XEntry Team is a threat actor associated with BitLocker-based extortion activity in Latin America, most clearly identified in an intrusion affecting an organization in Mexico. The actor abused exposed and misconfigured enterprise services rather than deploying a conventional ransomware family, relying heavily on legitimate Microsoft functionality and remote management software to expand access, maintain persistence, and encrypt systems at scale. In the Mexico intrusion, XEntry Team gained initial access through a misconfigured internet-exposed Microsoft SQL Server after obtaining valid database credentials from insecurely exposed code. The actor used operating-system command execution via SQL Server, attempted to weaken web server protections, created web shells, moved from the initial foothold into internal systems, and accessed systems containing configuration data for networking, enterprise management, and cloud services. For persistence and post-compromise operations, the actor deployed multiple remote monitoring and management tools, including ManageEngine Endpoint Central, Mesh Agent, and Tactical RMM. The actor then used scheduled tasks and Group Policy to activate BitLocker across domain-connected systems, collect recovery keys, and propagate encryption activity through the environment. Victims observed blue-screen messages claiming compromise by XEntry Team, lost access to credentials, and later received printed ransom notes through corporate printers. The actor’s tradecraft demonstrates initial access through exposed services and valid credentials, persistence through legitimate administration tooling, post-exploitation across Windows enterprise environments, and extortion through native disk encryption rather than custom locker malware. Reporting also notes similarities between the Mexico intrusion and a separate BitLocker-based extortion incident in Colombia, including ransom-note delivery via printers and abuse of BitLocker, but a definitive attribution of the Colombia case to XEntry Team is not established at high confidence.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
18 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducted BitLocker-based extortion in Mexico after exploiting a misconfigured internet-exposed MSSQL service, using xp_cmdshell for command execution, web shells, RMM tools, scheduled tasks, GPO deployment, and printer-delivered ransom notes.
Conducted a ransomware-style intrusion in Mexico by abusing a misconfigured internet-exposed MSSQL server, using xp_cmdshell for command execution, deploying multiple RMM tools for persistence and lateral operations, enabling BitLocker across systems via scheduled tasks and GPO, and printing ransom notes on corporate printers.
Ransom-motivated intrusion in Mexico involving exploitation of a misconfigured internet-exposed MSSQL service, use of stolen database credentials from code published on GitHub, deployment of RMM tools for persistence and command execution, abuse of GPO and BitLocker to encrypt systems, and printing ransom notes via corporate printers.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.