Security News > 2022 > September > Microsoft: Iranian hackers encrypt Windows systems using BitLocker
Microsoft says an Iranian state-sponsored threat group it tracks as DEV-0270 has been abusing the BitLocker Windows feature in attacks to encrypt victims' systems.
This aligns with Microsoft's findings that DEV-0270 uses BitLocker, a data protection feature that provides full volume encryption on devices running Windows 10, Windows 11, or Windows Server 2016 and above.
"DEV-0270 has been seen using setup.bat commands to enable BitLocker encryption, which leads to the hosts becoming inoperable," the Microsoft Security Threat Intelligence explained.
"For workstations, the group uses DiskCryptor, an open-source full disk encryption system for Windows that allows for the encryption of a device's entire hard drive."
The time to ransom between the initial access and the ransom note being deployed on locked systems was around two days, and DEV-0270 has been observed demanding victims to pay $8,000 for decryption keys following successful attacks.
Based on "Numerous infrastructure overlaps," Microsoft says the group is being operated by an Iranian company known under two aliases: Secnerd and Lifeweb.
News URL
Related news
- Microsoft says premature patch could make Windows Recall forget how to work (source)
- Microsoft says having a TPM is "non-negotiable" for Windows 11 (source)
- Microsoft dangles $10K for hackers to hijack LLM email service (source)
- Microsoft lifts Windows 11 24H2 block on PCs with USB scanners (source)
- Hackers Use Microsoft MSC Files to Deploy Obfuscated Backdoor in Pakistan Attacks (source)
- Microsoft says Auto HDR causes game freezes on Windows 11 24H2 (source)
- Microsoft adds another problem to the Windows 11 24H2 naughty list (source)
- Microsoft may have scrapped Windows 11's dynamic wallpapers feature (source)
- Microsoft to force install new Outlook on Windows 10 PCs in February (source)
- Microsoft: macOS bug lets hackers install malicious kernel drivers (source)