ATT&CKSoftwareShrinkLocker

ShrinkLocker

S1178

Malware.View on attack.mitre.org

About this malware

ShrinkLocker is a VBS-based malicious script that leverages the legitimate Bitlocker application to encrypt files on victim systems for ransom. ShrinkLocker functions by using Bitlocker to encrypt files, then renames impacted drives to the adversary’s contact email address to facilitate communication for the ransom payment.

Techniques used21

Procedure examples21

TechniqueProcedure example
T1016
System Network Configuration Discovery

ShrinkLocker captures the IP address of the victim system and sends this to the attacker following encryption.

T1041
Exfiltration Over C2 Channel

ShrinkLocker will exfiltrate victim system information along with the encryption key via an HTTP POST.

T1047
Windows Management Instrumentation

ShrinkLocker uses WMI to query information about the victim operating system.

T1057
Process Discovery

ShrinkLocker checks whether the Bitlocker Drive Encryption Tools service is running.

T1059.001
PowerShell

ShrinkLocker uses PowerShell to disable protectors used to secure the BitLocker encryption key on victim machines and then delete the key from the system.

T1059.005
Visual Basic

ShrinkLocker is a VisualBasic script (VBS) object that calls multiple other operating system functions during execution.

T1070.004
File Deletion

ShrinkLocker can delete itself depending on various checks performed during execution.

T1071.001
Web Protocols

ShrinkLocker uses HTTP POST requests to communicate victim information back to the threat actor.

T1082
System Information Discovery

ShrinkLocker uses WMI queries to gather various information about the victim machine and operating system.

T1102
Web Service

ShrinkLocker uses a subdomain on the legitimate Cloudflare resource "trycloudflare[.]com" to obfuscate the threat actor's actual address and to tunnel information sent from victim systems.

T1112
Modify Registry

ShrinkLocker modifies various registry keys associated with system logon and BitLocker functionality to effectively lock-out users following disk encryption.

T1124
System Time Discovery

ShrinkLocker retrieves a system timestamp that is used in generating an encryption key.

T1480
Execution Guardrails

ShrinkLocker will exit its "main" function if the victim domain name does not match provided criteria.

T1485
Data Destruction

ShrinkLocker can initiate a destructive payload depending on the operating system check through resizing and reformatting portions of the victim machine's disk, leading to system instability and potential data corruption.

T1486
Data Encrypted for Impact

ShrinkLocker uses the legitimate BitLocker application to encrypt victim files for ransom.

View all 21 procedure examples

Groups that use it0

None recorded.

Campaigns0

None recorded.

References2

  1. Kaspersky ShrinkLocker 2024 Open source
    Cristian Souza, Eduardo Ovalle, Ashley Muñoz, & Christopher Zachor. (2024, May 23). ShrinkLocker: Turning BitLocker into ransomware. Retrieved December 7, 2024.
  2. Splunk ShrinkLocker 2024 Open source
    Splunk Threat Research Team , Teoderick Contreras. (2024, September 5). ShrinkLocker Malware: Abusing BitLocker to Lock Your Data. Retrieved December 7, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.