Sunday, 19 October 2025
30 C
Singapore
28.9 C
Thailand
21.8 C
Indonesia
27.7 C
Philippines

New ransomware exploiting Windows BitLocker discovered

A new ransomware strain, ShrinkLocker, uses Windows BitLocker to encrypt files, targeting government agencies and manufacturing firms.

Cybersecurity researchers recently uncovered a new strain of ransomware that utilises Windows BitLocker to lock users out of their devices. Dubbed ShrinkLocker by Kaspersky, this ransomware has been observed targeting government agencies and firms in the manufacturing and pharmaceutical sectors.

How ShrinkLocker works

When ShrinkLocker infects a system, it shrinks available non-boot partitions by 100 MB and creates new primary boot volumes of the same size. It then uses BitLocker, a feature in some versions of Microsoft Windows, to encrypt the files on the device.

Unlike other ransomware variants, ShrinkLocker does not leave a ransom note. Instead, it labels new boot partitions with email addresses, presumably encouraging victims to communicate through this channel. Additionally, ShrinkLocker deletes all BitLocker protectors after encrypting the files, leaving victims with no way to recover the encryption key. The attackers hold the key, obtained through TryCloudflare, a legitimate tool developers use to test CloudFlare’s tunnel without adding a site to CloudFlare’s DNS.

Previous incidents of BitLocker-based attacks

While ShrinkLocker is not the first ransomware to use BitLocker, it does introduce new features to increase the attack’s impact. In the past, a hospital in Belgium fell victim to a ransomware strain that encrypted 100 TB of data on 40 servers using BitLocker. Similarly, Miratorg Holding, a meat producer and distributor in Russia, suffered a similar fate in 2022.

International impact

ShrinkLocker has already affected organisations in Mexico, Indonesia, and Jordan, including steel and vaccine manufacturing companies. The full extent of the damage caused by this ransomware is yet to be determined.

Hot this week

Square Enix unveils new Dissidia Final Fantasy after eight years, but fans are disappointed by mobile exclusivity

Square Enix announces a new Dissidia Final Fantasy for mobile, but fans express disappointment after eight years without a mainline release.

Apple upgrades Vision Pro with M5 chip and redesigned headband

Apple updates the Vision Pro with the M5 chip, improved visuals, better comfort, and longer battery life, launching in Singapore on 22 October.

New study reveals rise of ‘AI natives’ shaping customer and workplace expectations in Asia Pacific

A Zoom study highlights the rise of ‘AI natives’ in Asia Pacific, revealing their growing impact on customer experience and workplace expectations.

NVIDIA Spectrum-X Ethernet switches power next-generation AI data centres for Meta and Oracle

Meta and Oracle adopt NVIDIA Spectrum-X Ethernet switches to boost AI data centre performance and accelerate giga-scale model training.

Pixel 10 Pro Fold review: Google’s most polished and capable foldable yet

The Pixel 10 Pro Fold combines premium design, powerful AI, strong performance and advanced cameras in Google’s most refined foldable yet.

Samsung partners with Nvidia to develop custom CPUs and XPUs for AI dominance

Nvidia partners with Samsung to develop custom CPUs and XPUs, expanding its NVLink Fusion ecosystem to strengthen its AI hardware dominance.

NVIDIA unveils first US-made Blackwell wafer as domestic chip production expands

NVIDIA unveils its first US-made Blackwell wafer at TSMC’s Arizona facility, marking a major milestone in domestic AI chip production.

8BitDo unveils NES40 collection to mark 40 years of the Nintendo Entertainment System

8BitDo marks 40 years of the NES with a limited NES40 collection featuring redesigned controllers, a premium keyboard, and a modernised speaker.

Facebook’s new AI feature scans users’ camera rolls for unpublished photos

Facebook’s new AI tool scans users’ camera rolls to suggest edits and collages, raising questions about data use and privacy.

Related Articles