ShrinkLocker: Turning BitLocker into ransomware


The original purpose of BitLocker is to address the risks of data theft or exposure from lost, stolen, or improperly decommissioned devices.

Nonetheless, threat actors have found out that this mechanism can be repurposed for malicious ends to great effect. In that incident, the attackers were able to deploy and run an advanced VBS script that took advantage of BitLocker for unauthorized file encryption. We spotted this script and its modified versions in Mexico, Indonesia, and Jordan. In the sections below, we analyze in detail the malicious code obtained during our incident response effort and provide tips for mitigating this kind of threat.

Read more…
Source: Kaspersky


Sign up for our Newsletter


Related:

  • WikiLeaks Vault 7: CIA’s “Pandemic” Tool Replaces Files with Malware

    June 2, 2017

    WikiLeaks has released a new set of documents from its Vault 7 series, this time detailing a tool that the CIA allegedly uses to spread malware on a targeted organization’s network. Appropriately called “Pandemic,” the tool can install a file system filter driver on a network, replacing legitimate files with malicious payload when they are accessed ...

  • OneLogin Affected by Data Breach, Attacker May Have Decrypted Data

    June 2, 2017

    Access manager service OneLogin has announced that it has suffered a massive data breach that affects all users whose data was stored on the US servers, making for a rather nasty situation. “Our review has shown that a threat actor obtained access to a set of AWS keys and used them to access the AWS API ...

  • Financial malware more than twice as prevalent as ransomware

    June 1, 2017

    Three Trojans dominated the financial threat landscape in 2016 and attackers increased their focus on corporate finance departments With all the attention ransomware is getting lately it’s easy to overlook other threats, such as those that target the financial sector and its customers. However, these types of threats are a serious and costly problem for both ...

  • Group Behind NSA Dump That Led to WannaCry Opens 0-Day Exploit Subscription

    May 30, 2017

    Infamous hacking group Shadow Brokers has promised to release more zero-day exploits, such as the one that has made life a misery for some 300,000 people across the world via WannaCry. Now, the group isn’t just after wreaking havoc, but also after making some money, since the releases will be made for a special club ...

  • Naked photos and personal info from thousands of plastic surgery patients including dozens of celebrities and 1,500 Britons are published on the dark web

    May 30, 2017

    Hackers have published naked photos of thousands of plastic surgery patients who had work done at a Lithuanian clinic, it has been reported. Local authorities said more than 25,000 private photos and pieces of personal information from the Kaunas-based Grozio Chirurgija clinics were published on the internet. The leak includes intimate photos and data of more than ...

  • Linguistic Analysis Suggests WannaCry Hackers Could be From Southern China

    May 29, 2017

    It’s been almost four weeks since the outcry of WannaCry ransomware, but the hackers behind the self-spread ransomware threat have not been identified yet. However, two weeks ago researchers at Google, Kaspersky Lab, Intezer and Symantec linked WannaCry to ‘Lazarus Group,’ a state-sponsored hacking group believed to work for the North Korean government. Now, new research from ...