216.73.216.233

ShrinkLocker Malware: Abusing BitLocker to Lock Your Data

· Published 17/09/2024 11:15 · Modified 17/09/2024 11:28

Export JSON

Essential information

Published
17/09/2024 11:15
Modified
17/09/2024 11:28
Tags
2024-09-17 bitlocker disk partitioning encryption ransomware shrinklocker
Related entities
2 observables, 9 techniques (mitre), 1 malware

Description

is a new strain that exploits Windows to encrypt targeted data. Unlike typical , it abuses this legitimate feature to create a secure boot partition, locking users out unless a ransom is paid. The malware performs system checks, modifies registry entries, disables RDP, enforces smart card authentication, and alters settings. It shrinks disk partitions, formats new ones, and reconfigures boot files. generates a random key using system parameters and exfiltrates data to a C2 server. It also attempts to erase traces by deleting logs, firewall rules, and scheduled tasks. This sophisticated approach complicates decryption efforts and system recovery.

External references