logo

New GhostLock tool abuses Windows API to block file access

ID: b19ef2e1-a6bb-5b54-a5c2-2253a8570e53

STIX ID: report--b19ef2e1-a6bb-5b54-a5c2-2253a8570e53

Feed Name: Bleeping Computer

Threat Score
45/100

Date Published: 2026-05-11

Date Updated: 2026-05-11

Author: Lawrence Abrams

...
...

A researcher published GhostLock, a proof-of-concept tool and technique that abuses the Windows CreateFileW API (setting dwShareMode = 0) to open files with exclusive access and cause sharing-violation errors on local and SMB-hosted files; the attack can be performed by standard domain users, scaled from multiple hosts, and primarily creates temporary disruption (denial of access) rather than data destruction. The report notes detection is difficult for typical EDR and logging, provides defensive SIEM/NDR detection templates, and frames GhostLock as a disruption technique that could be used as a decoy during broader intrusions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.