ATT&CKReferencesSplunk ShrinkLocker 2024

Splunk ShrinkLocker 2024

Splunk Threat Research Team , Teoderick Contreras. (2024, September 5). ShrinkLocker Malware: Abusing BitLocker to Lock Your Data. Retrieved December 7, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples13

TechniqueUsed byProcedure example
T1041
Exfiltration Over C2 Channel
MalwareShrinkLocker

ShrinkLocker will exfiltrate victim system information along with the encryption key via an HTTP POST.

T1057
Process Discovery
MalwareShrinkLocker

ShrinkLocker checks whether the Bitlocker Drive Encryption Tools service is running.

T1059.005
Visual Basic
MalwareShrinkLocker

ShrinkLocker is a VisualBasic script (VBS) object that calls multiple other operating system functions during execution.

T1082
System Information Discovery
MalwareShrinkLocker

ShrinkLocker uses WMI queries to gather various information about the victim machine and operating system.

T1112
Modify Registry
MalwareShrinkLocker

ShrinkLocker modifies various registry keys associated with system logon and BitLocker functionality to effectively lock-out users following disk encryption.

T1124
System Time Discovery
MalwareShrinkLocker

ShrinkLocker retrieves a system timestamp that is used in generating an encryption key.

T1480
Execution Guardrails
MalwareShrinkLocker

ShrinkLocker will exit its "main" function if the victim domain name does not match provided criteria.

T1485
Data Destruction
MalwareShrinkLocker

ShrinkLocker can initiate a destructive payload depending on the operating system check through resizing and reformatting portions of the victim machine's disk, leading to system instability and potential data corruption.

T1486
Data Encrypted for Impact
MalwareShrinkLocker

ShrinkLocker uses the legitimate BitLocker application to encrypt victim files for ransom.

T1491.001
Internal Defacement
MalwareShrinkLocker

ShrinkLocker renames disk labels on victim hosts to the threat actor's email address to enable the victim to contact the threat actor for ransom negotiation.

T1561.002
Disk Structure Wipe
MalwareShrinkLocker

ShrinkLocker has used Diskpart to format newly-created partitions.

T1685
Disable or Modify Tools
MalwareShrinkLocker

ShrinkLocker disables protectors used to secure the BitLocker encryption key on victim systems.

T1686
Disable or Modify System Firewall
MalwareShrinkLocker

ShrinkLocker turns on the system firewall and deletes all of its rules during execution.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.