ATT&CKReferencesKaspersky ShrinkLocker 2024

Kaspersky ShrinkLocker 2024

Cristian Souza, Eduardo Ovalle, Ashley Muñoz, & Christopher Zachor. (2024, May 23). ShrinkLocker: Turning BitLocker into ransomware. Retrieved December 7, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples16

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareShrinkLocker

ShrinkLocker captures the IP address of the victim system and sends this to the attacker following encryption.

T1041
Exfiltration Over C2 Channel
MalwareShrinkLocker

ShrinkLocker will exfiltrate victim system information along with the encryption key via an HTTP POST.

T1047
Windows Management Instrumentation
MalwareShrinkLocker

ShrinkLocker uses WMI to query information about the victim operating system.

T1059.001
PowerShell
MalwareShrinkLocker

ShrinkLocker uses PowerShell to disable protectors used to secure the BitLocker encryption key on victim machines and then delete the key from the system.

T1059.005
Visual Basic
MalwareShrinkLocker

ShrinkLocker is a VisualBasic script (VBS) object that calls multiple other operating system functions during execution.

T1070.004
File Deletion
MalwareShrinkLocker

ShrinkLocker can delete itself depending on various checks performed during execution.

T1071.001
Web Protocols
MalwareShrinkLocker

ShrinkLocker uses HTTP POST requests to communicate victim information back to the threat actor.

T1082
System Information Discovery
MalwareShrinkLocker

ShrinkLocker uses WMI queries to gather various information about the victim machine and operating system.

T1102
Web Service
MalwareShrinkLocker

ShrinkLocker uses a subdomain on the legitimate Cloudflare resource "trycloudflare[.]com" to obfuscate the threat actor's actual address and to tunnel information sent from victim systems.

T1112
Modify Registry
MalwareShrinkLocker

ShrinkLocker modifies various registry keys associated with system logon and BitLocker functionality to effectively lock-out users following disk encryption.

T1486
Data Encrypted for Impact
MalwareShrinkLocker

ShrinkLocker uses the legitimate BitLocker application to encrypt victim files for ransom.

T1491.001
Internal Defacement
MalwareShrinkLocker

ShrinkLocker renames disk labels on victim hosts to the threat actor's email address to enable the victim to contact the threat actor for ransom negotiation.

T1529
System Shutdown/Reboot
MalwareShrinkLocker

ShrinkLocker can restart the victim system if it encounters an error during execution, and will forcibly shutdown the system following encryption to lock out victim users.

T1685
Disable or Modify Tools
MalwareShrinkLocker

ShrinkLocker disables protectors used to secure the BitLocker encryption key on victim systems.

T1685.005
Clear Windows Event Logs
MalwareShrinkLocker

ShrinkLocker calls Wevtutil to clear the Windows PowerShell and Microsoft-Windows-Powershell/Operational logs.

T1686
Disable or Modify System Firewall
MalwareShrinkLocker

ShrinkLocker turns on the system firewall and deletes all of its rules during execution.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.