logo

GhostLock Attack Leverages Windows file-sharing to Lock Files Access Like Ransomware

ID: d6525e02-1d57-52de-a02e-40bfedfb7efd

STIX ID: report--d6525e02-1d57-52de-a02e-40bfedfb7efd

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-05-11

Date Updated: 2026-05-14

Author: Guru Baran

...
...

GhostLock is a newly disclosed availability attack technique that abuses Windows SMB file locking (CreateFileW with dwShareMode = 0) to acquire exclusive handles on large numbers of files, making them inaccessible and producing the same operational impact as ransomware without encrypting data. Implemented as a low-privilege Python tool, it scales to hundreds of thousands of locked handles, evades common ransomware defenses and EDRs, and requires storage-operations intervention to recover; authors recommend exposing per-session exclusive-handle telemetry, SIEM ingestion, and joint SecOps/StorageOps runbooks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.