Bitlocker Ransomware: Using BitLocker for Nefarious Reasons
ID: 8dc457ea-df73-5638-bddb-b2de319660e1
STIX ID: report--8dc457ea-df73-5638-bddb-b2de319660e1
Feed Name: Black Hills Infosec Blog
This report shows a practical "BitLocker-based ransomware" technique: a PowerShell script using BitLocker cmdlets and registry policy changes to enable or reconfigure BitLocker, encrypt the OS drive, discard existing recovery keys, place a custom recovery message, and require a password known only to the attacker. The author demonstrates behavior, lists detection methods (BitLocker event logs, manage-bde/get-BitLockerVolume checks), provides defensive advice (backups, least privilege, monitoring), and notes Microsoft’s position that this is an abuse of admin privileges rather than a software vulnerability.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
