Security News > 2024 > May > What Is ShrinkLocker? New Ransomware Targets Microsoft BitLocker Encryption Feature
It exploits the Microsoft BitLocker encryption feature to encrypt the entire local drive and remove the recovery options before shutting down the PC. ShrinkLocker was discovered by cybersecurity firm Kaspersky, and analysts have observed variants in Mexico, Indonesia and Jordan.
BitLocker has been used to stage ransomware attacks in the past, but this strain has "Previously unreported features to maximise the damage of the attack," Kaspersky said in a press release.
Attackers might deploy ShrinkLocker on a device by exploiting unpatched vulnerabilities, stolen credentials or internet-facing services to gain access to servers.
In a technical analysis, Kaspersky analysts describe both the detection of a ShrinkLocker attack and the decryption process as "Difficult." The latter is particularly hard because the malicious script contains variables that are different for each affected system.
Kaspersky experts have, so far, not been able to identify the source of the ShrinkLocker attacks or where the decryption keys and other device information are sent.
The following year, another attacker targeted one of Russia's largest meat suppliers in the same way, before Microsoft reported the Iranian government had sponsored a number of BitLocker-based ransomware attacks that demanded thousands of U.S. dollars for the decryption key.
News URL
https://www.techrepublic.com/article/bitlocker-ransomware-shrinklocker/
Related news
- Microsoft says more ransomware stopped before reaching encryption (source)
- Microsoft Identifies Storm-0501 as Major Threat in Hybrid Cloud Ransomware Attacks (source)
- Ransomware gang using stolen Microsoft Entra ID creds to bust into the cloud (source)
- Ransomware attackers hop from on-premises systems to cloud to compromise Microsoft 365 accounts (source)
- Microsoft: Ransomware Attacks Growing More Dangerous, Complex (source)
- New Qilin ransomware encryptor features stronger encryption, evasion (source)
- New Qilin.B Ransomware Variant Emerges with Improved Encryption and Evasion Tactics (source)
- Black Basta ransomware poses as IT support on Microsoft Teams to breach networks (source)
- Free Decryptor Released for BitLocker-Based ShrinkLocker Ransomware Victims (source)
- New ShrinkLocker ransomware decryptor recovers BitLocker password (source)