Malware.View on attack.mitre.org
ShrinkLocker is a VBS-based malicious script that leverages the legitimate Bitlocker application to encrypt files on victim systems for ransom. ShrinkLocker functions by using Bitlocker to encrypt files, then renames impacted drives to the adversary’s contact email address to facilitate communication for the ransom payment.
| Technique | Procedure example |
|---|---|
| T1016 System Network Configuration Discovery |
ShrinkLocker captures the IP address of the victim system and sends this to the attacker following encryption. |
| T1041 Exfiltration Over C2 Channel |
ShrinkLocker will exfiltrate victim system information along with the encryption key via an HTTP POST. |
| T1047 Windows Management Instrumentation |
ShrinkLocker uses WMI to query information about the victim operating system. |
| T1057 Process Discovery |
ShrinkLocker checks whether the Bitlocker Drive Encryption Tools service is running. |
| T1059.001 PowerShell |
ShrinkLocker uses PowerShell to disable protectors used to secure the BitLocker encryption key on victim machines and then delete the key from the system. |
| T1059.005 Visual Basic |
ShrinkLocker is a VisualBasic script (VBS) object that calls multiple other operating system functions during execution. |
| T1070.004 File Deletion |
ShrinkLocker can delete itself depending on various checks performed during execution. |
| T1071.001 Web Protocols |
ShrinkLocker uses HTTP POST requests to communicate victim information back to the threat actor. |
| T1082 System Information Discovery |
ShrinkLocker uses WMI queries to gather various information about the victim machine and operating system. |
| T1102 Web Service |
ShrinkLocker uses a subdomain on the legitimate Cloudflare resource "trycloudflare[.]com" to obfuscate the threat actor's actual address and to tunnel information sent from victim systems. |
| T1112 Modify Registry |
ShrinkLocker modifies various registry keys associated with system logon and BitLocker functionality to effectively lock-out users following disk encryption. |
| T1124 System Time Discovery |
ShrinkLocker retrieves a system timestamp that is used in generating an encryption key. |
| T1480 Execution Guardrails |
ShrinkLocker will exit its "main" function if the victim domain name does not match provided criteria. |
| T1485 Data Destruction |
ShrinkLocker can initiate a destructive payload depending on the operating system check through resizing and reformatting portions of the victim machine's disk, leading to system instability and potential data corruption. |
| T1486 Data Encrypted for Impact |
ShrinkLocker uses the legitimate BitLocker application to encrypt victim files for ransom. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.