logo

Here's yet more ransomware using BitLocker against Microsoft's own users

ID: 7e24b196-1a92-5acf-a773-8d5985eb4300

STIX ID: report--7e24b196-1a92-5acf-a773-8d5985eb4300

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2024-05-23

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Kaspersky's researchers identified ShrinkLocker, a ransomware strain observed in Mexico, Indonesia, and Jordan that leverages VBScript and WMI to detect OS versions, resizes partitions and configures BitLocker on infected Windows systems, exfiltrates BitLocker recovery keys to an attacker-controlled server, deletes local recovery options and logs, then forces shutdown to present a ransom/BitLocker recovery screen; the report includes IOCs, detection tips, and mitigation recommendations such as restricting privileges, protecting recovery keys, logging execution events, and maintaining tested offline backups.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.