Splunk Threat Research Team , Teoderick Contreras. (2024, September 5). ShrinkLocker Malware: Abusing BitLocker to Lock Your Data. Retrieved December 7, 2024.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1041 Exfiltration Over C2 Channel |
MalwareShrinkLocker | ShrinkLocker will exfiltrate victim system information along with the encryption key via an HTTP POST. |
| T1057 Process Discovery |
MalwareShrinkLocker | ShrinkLocker checks whether the Bitlocker Drive Encryption Tools service is running. |
| T1059.005 Visual Basic |
MalwareShrinkLocker | ShrinkLocker is a VisualBasic script (VBS) object that calls multiple other operating system functions during execution. |
| T1082 System Information Discovery |
MalwareShrinkLocker | ShrinkLocker uses WMI queries to gather various information about the victim machine and operating system. |
| T1112 Modify Registry |
MalwareShrinkLocker | ShrinkLocker modifies various registry keys associated with system logon and BitLocker functionality to effectively lock-out users following disk encryption. |
| T1124 System Time Discovery |
MalwareShrinkLocker | ShrinkLocker retrieves a system timestamp that is used in generating an encryption key. |
| T1480 Execution Guardrails |
MalwareShrinkLocker | ShrinkLocker will exit its "main" function if the victim domain name does not match provided criteria. |
| T1485 Data Destruction |
MalwareShrinkLocker | ShrinkLocker can initiate a destructive payload depending on the operating system check through resizing and reformatting portions of the victim machine's disk, leading to system instability and potential data corruption. |
| T1486 Data Encrypted for Impact |
MalwareShrinkLocker | ShrinkLocker uses the legitimate BitLocker application to encrypt victim files for ransom. |
| T1491.001 Internal Defacement |
MalwareShrinkLocker | ShrinkLocker renames disk labels on victim hosts to the threat actor's email address to enable the victim to contact the threat actor for ransom negotiation. |
| T1561.002 Disk Structure Wipe |
MalwareShrinkLocker | ShrinkLocker has used Diskpart to format newly-created partitions. |
| T1685 Disable or Modify Tools |
MalwareShrinkLocker | ShrinkLocker disables protectors used to secure the BitLocker encryption key on victim systems. |
| T1686 Disable or Modify System Firewall |
MalwareShrinkLocker | ShrinkLocker turns on the system firewall and deletes all of its rules during execution. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.