Description
ShrinkLocker is ransomware written in VBScript that encrypts files and uses BitLocker, the disk encryption feature built into Windows, to lock infected systems. Rather than bringing its own cryptography, it repurposes enterprise encryption management, which makes the attack look like legitimate administrative activity while systems become inaccessible. The approach reflects a broader trend of ransomware abusing native security tools, and defenders should monitor BitLocker changes closely.
Stats
- First seen
- May 2024
- Last seen
- October 2026
MITRE ATT&CK techniques
21 techniques across 7 tactics.
Alert name variants
| Alert Name |
|---|
| Dump:Generic.VBS.ShrinkLocker.B.FFFFFFFE |
| Generic.VBS.ShrinkLocker.A.07D2AC86 |
| Generic.VBS.ShrinkLocker.A.09099AC9 |
| Generic.VBS.ShrinkLocker.A.1622CAC4 |
| Generic.VBS.ShrinkLocker.A.1D47F9F4 |
| Generic.VBS.ShrinkLocker.A.1D8BF9D8 |
| Generic.VBS.ShrinkLocker.A.23820C7D |
| Generic.VBS.ShrinkLocker.A.382B3344 |
| Generic.VBS.ShrinkLocker.A.3EA36EC4 |
| Generic.VBS.ShrinkLocker.A.420C7792 |