Tag

Shrinklocker

All articles tagged with #shrinklocker

cybersecurity1 year ago

"ShrinkLocker Ransomware Exploits BitLocker to Encrypt Data"

A new ransomware called ShrinkLocker uses Windows' BitLocker feature to encrypt victim data, targeting systems in Mexico, Indonesia, and Jordan. Discovered by Kaspersky, ShrinkLocker shrinks non-boot partitions and creates new primary partitions, then disables BitLocker protections and generates a complex encryption key. Kaspersky advises robust endpoint protection, minimal user privileges, and frequent offline backups to mitigate risks.

cybersecurity1 year ago

ShrinkLocker Ransomware Exploits Microsoft BitLocker for File Encryption

A new ransomware strain called ShrinkLocker uses Windows BitLocker to encrypt files by creating new boot partitions, targeting government entities and companies in the vaccine and manufacturing sectors. Written in VBScript, ShrinkLocker detects specific Windows versions and modifies registry entries to disable remote desktop connections and enable BitLocker encryption without a TPM. The malware deletes BitLocker protectors to prevent recovery and uses TryCloudflare to deliver encryption keys. Kaspersky advises secure storage of recovery keys and regular offline backups to mitigate such attacks.