Cristian Souza, Eduardo Ovalle, Ashley Muñoz, & Christopher Zachor. (2024, May 23). ShrinkLocker: Turning BitLocker into ransomware. Retrieved December 7, 2024.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
MalwareShrinkLocker | ShrinkLocker captures the IP address of the victim system and sends this to the attacker following encryption. |
| T1041 Exfiltration Over C2 Channel |
MalwareShrinkLocker | ShrinkLocker will exfiltrate victim system information along with the encryption key via an HTTP POST. |
| T1047 Windows Management Instrumentation |
MalwareShrinkLocker | ShrinkLocker uses WMI to query information about the victim operating system. |
| T1059.001 PowerShell |
MalwareShrinkLocker | ShrinkLocker uses PowerShell to disable protectors used to secure the BitLocker encryption key on victim machines and then delete the key from the system. |
| T1059.005 Visual Basic |
MalwareShrinkLocker | ShrinkLocker is a VisualBasic script (VBS) object that calls multiple other operating system functions during execution. |
| T1070.004 File Deletion |
MalwareShrinkLocker | ShrinkLocker can delete itself depending on various checks performed during execution. |
| T1071.001 Web Protocols |
MalwareShrinkLocker | ShrinkLocker uses HTTP POST requests to communicate victim information back to the threat actor. |
| T1082 System Information Discovery |
MalwareShrinkLocker | ShrinkLocker uses WMI queries to gather various information about the victim machine and operating system. |
| T1102 Web Service |
MalwareShrinkLocker | ShrinkLocker uses a subdomain on the legitimate Cloudflare resource "trycloudflare[.]com" to obfuscate the threat actor's actual address and to tunnel information sent from victim systems. |
| T1112 Modify Registry |
MalwareShrinkLocker | ShrinkLocker modifies various registry keys associated with system logon and BitLocker functionality to effectively lock-out users following disk encryption. |
| T1486 Data Encrypted for Impact |
MalwareShrinkLocker | ShrinkLocker uses the legitimate BitLocker application to encrypt victim files for ransom. |
| T1491.001 Internal Defacement |
MalwareShrinkLocker | ShrinkLocker renames disk labels on victim hosts to the threat actor's email address to enable the victim to contact the threat actor for ransom negotiation. |
| T1529 System Shutdown/Reboot |
MalwareShrinkLocker | ShrinkLocker can restart the victim system if it encounters an error during execution, and will forcibly shutdown the system following encryption to lock out victim users. |
| T1685 Disable or Modify Tools |
MalwareShrinkLocker | ShrinkLocker disables protectors used to secure the BitLocker encryption key on victim systems. |
| T1685.005 Clear Windows Event Logs |
MalwareShrinkLocker | ShrinkLocker calls Wevtutil to clear the Windows PowerShell and Microsoft-Windows-Powershell/Operational logs. |
| T1686 Disable or Modify System Firewall |
MalwareShrinkLocker | ShrinkLocker turns on the system firewall and deletes all of its rules during execution. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.