Sunday, 19 January 2025
24.9 C
Singapore

New ransomware exploiting Windows BitLocker discovered

A new ransomware strain, ShrinkLocker, uses Windows BitLocker to encrypt files, targeting government agencies and manufacturing firms.

Cybersecurity researchers recently uncovered a new strain of ransomware that utilises Windowsย BitLocker to lock users out of their devices. Dubbed ShrinkLocker by Kaspersky, this ransomware hasย been observedย targeting government agencies and firms in the manufacturing and pharmaceutical sectors.

How ShrinkLocker works

When ShrinkLocker infects a system, it shrinks available non-boot partitions by 100 MB and creates new primary boot volumes of the same size. It then uses BitLocker, a feature in some versions ofย Microsoftย Windows, to encrypt the files on the device.

Unlike other ransomware variants, ShrinkLocker does not leave a ransom note. Instead, it labels new boot partitions with email addresses, presumably encouraging victims to communicate through this channel. Additionally, ShrinkLocker deletes all BitLocker protectors after encrypting the files, leaving victims with no way to recover the encryption key. The attackers hold the key, obtained through TryCloudflare, a legitimate tool developers use to test CloudFlare’s tunnel without adding a site to CloudFlare’s DNS.

Previous incidents of BitLocker-based attacks

While ShrinkLocker is not the first ransomware to use BitLocker, it does introduce new features to increase the attack’s impact. In the past, a hospital in Belgium fell victim to a ransomware strain that encrypted 100 TB of data on 40 servers using BitLocker. Similarly, Miratorg Holding, a meat producer and distributor in Russia, suffered a similar fate in 2022.

International impact

ShrinkLocker has already affected organisations in Mexico, Indonesia, and Jordan, including steel and vaccine manufacturing companies. The full extent of the damage caused by this ransomware is yet to be determined.

Hot this week

Proofpoint recognised as a leader in Gartner report for digital communications governance and archiving solutions

Proofpoint named a leader in 2025 Gartner Magic Quadrant for digital communications governance and archiving, excelling in vision and execution.

More applicants but harder to hire: LinkedIn highlights hiring challenges in 2025

LinkedIn's 2025 research highlights hiring struggles in APAC, driven by a skills mismatch, rising AI demands, and new tools to address these challenges.

Arlo announces partnership with Origin AI to enhance smart home security

Arlo partners with Origin AI to deliver cutting-edge AI-powered home security, integrating exclusive technologies like TruShield and Allos.

Amazon pauses drone deliveries in the US after testing crash

Amazon halts US drone deliveries after crashes during testing, citing safety concerns and working on software updates for its fleet.

JLR and Tata Communications join forces to create smarter connected vehicles

JLR and Tata Communications team up to redefine connected luxury vehicles, offering smarter features, real-time updates, and global connectivity.

Character AI tests games on its platform to boost user engagement

Character AI introduces games to its platform to boost user engagement and enhance its entertainment offerings.

How to download your TikTok videos and data before the ban

The Supreme Court has upheld a TikTok ban, and hereโ€™s how you can back up your videos and data before it happens.

ChatGPTโ€™s head of product to testify in US antitrust case against Google

ChatGPTโ€™s head of product, Nick Turley, will testify in the US governmentโ€™s antitrust case against Google, addressing AI and competition issues.

Amazon pauses drone deliveries in the US after testing crash

Amazon halts US drone deliveries after crashes during testing, citing safety concerns and working on software updates for its fleet.

Related Articles