New ShrinkLocker ransomware uses BitLocker to encrypt your files
ID: 8e99bdee-0f97-5c63-b602-dfa1f32c83e4
STIX ID: report--8e99bdee-0f97-5c63-b602-dfa1f32c83e4
Feed Name: Bleeping Computer
ShrinkLocker is a VBScript ransomware that abuses native Windows features—shrinking non-boot partitions to create new boot volumes, reinstalling boot files with BCDEdit, and enabling BitLocker while deleting recovery protectors—to lock systems and deny recovery; it has been observed against a government entity and organizations in the steel and vaccine manufacturing sectors across multiple countries, uses contact emails embedded as boot volume labels instead of a visible ransom note, and leverages legitimate services (TryCloudflare) to exfiltrate encryption keys.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
