logo

ShrinkLocker: Turning BitLocker into ransomware

ID: 2e8ce92e-dcb3-5d38-90ac-e212dc0e1c11

STIX ID: report--2e8ce92e-dcb3-5d38-90ac-e212dc0e1c11

Feed Name: Securelist by Kaspersky

Threat Score
75/100

Date Published: 2024-05-23

Date Updated: 2026-04-29

Author: Cristian Souza, Eduardo Ovalle, Ashley Muñoz, Christopher Zachor

...
...

This report analyzes a VBScript ransomware campaign that abuses Windows BitLocker to encrypt entire drives: the script resizes partitions, reinstalls boot files, removes BitLocker key protectors, generates a 64-character password seeded from system data, enables BitLocker with that password, exfiltrates machine and key data via POST requests (using Cloudflare tunnels), clears logs and tasks, and forces a reboot to present a BitLocker recovery screen. The analysis includes MITRE TTP mapping, IOCs (domains, e-mails, MD5), forensic findings, and mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.