la-villa-hacker-logo-transparente
  • Nosotros
  • Conferencistas
  • Blog
  • Contacto
la-villa-hacker-logo-transparente
  • Nosotros
  • Conferencistas
  • Blog
  • Contacto
  • Nosotros
  • Conferencistas
  • Blog
  • Contacto
la-villa-hacker-logo-transparente
la-villa-hacker-logo-transparente
  • Nosotros
  • Conferencistas
  • Blog
  • Contacto
TEAM
HomeTeamEduardo Chavarro
Eduardo-chavarro
DFIR Group Manager | Kaspersky - GERT

Eduardo Chavarro

Eduardo Chavarro Ovalle, DFIR Group Manager for Americas, member of Kaspersky GERT Team. Student of DBA in ML and AI and MSc in Cybersecurity with more than 20 years of experience in cybersecurity, DFIR, eDiscovery, and threat analysis. GCIH | GRID | GCFA | CISM | CHFI | CPTE | SFCP | ITIL.
EMAIL:
eduardo.ovalle@kaspersky.com

Resumen de la Charla

Our GERT team was notified about a company affected by a previously unknown threat actor identified as “XEntry Team”. Initially, the customer identified this threat as a hijacked LogMeIn session that allowed the attackers to activate BitLocker and encrypt the disks of every system synchronizing to the AD; but our analysis confirmed a 2 months intrusion, using a mix of clever techniques and lack of monitoring, that allowed attacker to configure a bridge to the infrastructure for:
• Recognition
• Critical assets identification
• Exfiltration
• Persistance
• ransomware deployment
• Other not so funny stuff.

During this session we will present to the audience the investigation results, the techniques implemented by the threat actor, the scope of the attack from beginning to the end, and the analysis and attempts to recover affected systems.

CHARLA

Meet XEntry Team: A powerful threat actor abusing Bitlocker for ransomware

 
contacto@lavillahacker.com

Nevada, USA

X-twitterLinkedin-inInstagram

La Villa Hacker

Nosotros
Conferencistas
Blog
Contacto
la-villa-hacker-logo-transparente

Copyright © 2026 La Villa Hacker. Todos los derechos reservados