Friday, 7 November 2025
30 C
Singapore
26.5 C
Thailand
21.5 C
Indonesia
28.1 C
Philippines

New ransomware exploiting Windows BitLocker discovered

A new ransomware strain, ShrinkLocker, uses Windows BitLocker to encrypt files, targeting government agencies and manufacturing firms.

Cybersecurity researchers recently uncovered a new strain of ransomware that utilises Windows BitLocker to lock users out of their devices. Dubbed ShrinkLocker by Kaspersky, this ransomware has been observed targeting government agencies and firms in the manufacturing and pharmaceutical sectors.

How ShrinkLocker works

When ShrinkLocker infects a system, it shrinks available non-boot partitions by 100 MB and creates new primary boot volumes of the same size. It then uses BitLocker, a feature in some versions of Microsoft Windows, to encrypt the files on the device.

Unlike other ransomware variants, ShrinkLocker does not leave a ransom note. Instead, it labels new boot partitions with email addresses, presumably encouraging victims to communicate through this channel. Additionally, ShrinkLocker deletes all BitLocker protectors after encrypting the files, leaving victims with no way to recover the encryption key. The attackers hold the key, obtained through TryCloudflare, a legitimate tool developers use to test CloudFlare’s tunnel without adding a site to CloudFlare’s DNS.

Previous incidents of BitLocker-based attacks

While ShrinkLocker is not the first ransomware to use BitLocker, it does introduce new features to increase the attack’s impact. In the past, a hospital in Belgium fell victim to a ransomware strain that encrypted 100 TB of data on 40 servers using BitLocker. Similarly, Miratorg Holding, a meat producer and distributor in Russia, suffered a similar fate in 2022.

International impact

ShrinkLocker has already affected organisations in Mexico, Indonesia, and Jordan, including steel and vaccine manufacturing companies. The full extent of the damage caused by this ransomware is yet to be determined.

Hot this week

Affiliate marketing becomes major growth driver for brands in Singapore as investments surge

Affiliate marketing becomes a core growth channel for Singapore brands as investment rises and creators gain greater influence.

WhatsApp reportedly testing companion app for Apple Watch

WhatsApp is testing a companion app for Apple Watch, allowing users to view and reply to messages directly from their wrist.

Milestone Systems unveils generative AI plug-in for XProtect to streamline video analysis

Milestone Systems introduces a generative AI plug-in for XProtect, developed with NVIDIA to automate video review and reduce alarm fatigue.

Square Enix cuts UK and US jobs as it shifts focus back to Japan

Square Enix lays off UK and US developers as it consolidates operations in Japan and expands its use of AI in game development.

Canon introduces EOS R6 Mark III and RF45mm f/1.2 STM for creators and enthusiasts

Canon unveils the EOS R6 Mark III and RF45mm f/1.2 STM, offering high-end imaging and video performance for creators and enthusiasts.

Meta introduces a quick connect shortcut for smart glasses

Meta’s new quick connect feature lets smart glasses users call or text with one touch, reducing reliance on “hey Meta” voice commands.

Square Enix cuts UK and US jobs as it shifts focus back to Japan

Square Enix lays off UK and US developers as it consolidates operations in Japan and expands its use of AI in game development.

Evotrex unveils hybrid RV trailer powered by battery and petrol engine

Former Anker employees launch Evotrex, a hybrid RV startup combining battery and petrol power to extend off-grid travel adventures.

Devialet: How Phantom Ultimate reflects the future of compact high-end sound

Devialet’s Phantom Ultimate shows how innovation, software, sustainability, and design are shaping the next era of compact high-end audio.

Related Articles

Popular Categories