
Fake Install Guides and Helpdesk Calls Drive Attacks
This bulletin describes multiple real-world social engineering campaigns where attackers trick people into trusting a familiar screen, like a search result…
Two real incidents in Colombia and Mexico show attackers using built-in Windows BitLocker to lock company drives, then printing ransom notes from office printers to pressure victims to pay. One case started from an exposed Remote Desktop (RDP) service; the other began from a misconfigured Microsoft SQL Server where credentials were found in code posted on GitHub. The attackers demanded relatively small ransoms (example: $3,000) and used “reputation” language in their messages to convince victims they would provide recovery help after payment.
In both incidents described, attackers did not need custom malware to lock victims out of their data. Instead, they abused BitLocker, a legitimate Windows disk encryption feature, to lock drives after gaining a foothold in the network. In the Colombia case, initial access came through an internet-exposed RDP service. In the Mexico case, attackers exploited a misconfigured MSSQL service and used database credentials that had been published in code on GitHub. Once inside, attackers manipulated credentials, enabled BitLocker on drives holding sensitive data, and then used office printers to physically print ransom notes throughout the workplace, turning ordinary office equipment into a delivery channel for extortion messages.
The attacks relied on a mix of technical access and psychological pressure. Ransom notes used reassuring, business-like language about the attackers' "reputation" as a guarantee they would help recover data after payment, which is intended to make the extortion feel more like a transaction than a crime. The Mexico case also involved spreading encryption widely using RMM tools and group policy, escalating a single point of access into an organization-wide event. In both cases, security tooling and alerts existed, but investigation gaps meant early warning signs were not acted on in time to stop the final encryption stage.
Organizations can reduce exposure by closing off internet-facing RDP and misconfigured database services, and by carefully managing credentials so they are never left in code repositories. Just as important is response discipline: alerts from existing security controls need to be investigated and closed rather than left unresolved, since alert fatigue can give attackers the time needed to complete encryption. When an incident does occur, preserving logs and system state for forensic review is critical. In one of these cases, systems were restored quickly, which eliminated the evidence needed to fully understand how access occurred and to prevent a repeat attack. Training employees, especially IT, helpdesk, finance, and operations staff, to treat unexpected printer output or sudden credential failures as an active incident rather than a technical glitch can help shorten the time between compromise and response.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
In one case attackers exploited an internet-exposed RDP service, and in the other they exploited a misconfigured MSSQL service and found database credentials published in code on GitHub.
After locking drives with BitLocker, attackers used the company printers to physically distribute ransom notes across the workplace, creating urgency and visibility for the extortion demand.
Security controls generated alerts and blocked some attempts, but the necessary investigation was not carried out in time, which gave attackers the opportunity to complete encryption.
Unexpected printer output demanding payment should be treated as an active security incident and reported to IT or Security immediately rather than dismissed.
Imagine you’re at your desk…and every office printer suddenly spits out the same ransom note. This really happened. In Colombia and Mexico, attackers used Windows BitLocker to lock company drives, then hijacked office printers to drop $3,000 ransom notes claiming their 'reputation' guaranteed recovery. In one case, users saw a blue screen saying 'Hacked by XEntry Team', lost access to their accounts, and hours later ransom notes started printing, pressuring them to email the extortion address and pay fast. Your move: if a printer ever spits out a ransom note or payment demand, don’t call the email on the page, call IT or Security immediately and report it as a major incident.

This bulletin describes multiple real-world social engineering campaigns where attackers trick people into trusting a familiar screen, like a search result…

This weekly roundup describes multiple real-world campaigns where attackers trick people using familiar brands and “verification” prompts to steal credentials…

Researchers reported a months-long campaign where attackers used Microsoft Teams chats/calls while pretending to be IT/help desk support. Victims were talked…

South Korean agencies and AhnLab warn that tools tied to North Korea’s Lazarus Group appear to be shared with the Gunra ransomware operation targeting South…

A state-sponsored campaign in South Korea used spear-phishing and hacked “trusted” local websites to infect visitors who had vulnerable AnySign4PC installed.…

Russian-linked threat actors sent generic-looking informational emails that required no clicking, but simply opening them in vulnerable Outlook Web Access…