logo

OneDrive ransomware

ID: e5c397aa-049d-578a-b023-d47b3da52975

STIX ID: report--e5c397aa-049d-578a-b023-d47b3da52975

Feed Name: ThreatLocker Blog

Threat Score
70/100

Date Published: 2025-01-03

Date Updated: 2026-05-01

...
...

ThreatLocker researchers demonstrate “DoubleDrive,” a ransomware technique that leverages OneDrive synchronization and junction manipulation to delete local files, replicate them to OneDrive, and encrypt them—thereby disabling local recovery. The report identifies vulnerable OneDrive client versions, provides a timed demonstration of developing and deploying a malicious executable, and recommends application allowlisting and ringfencing as mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.