Netskope Threat Labs

ShrinkLocker

ATP Sandbox Adv. HeuristicsAV

ShrinkLocker is ransomware written in VBScript that encrypts files and uses BitLocker, the disk encryption feature built into Windows, to lock infected systems. Rather than bringing its own cryptography, it repurposes enterprise encryption management, which makes the attack look like legitimate administrative activity while systems become inaccessible. The approach reflects a broader trend of ransomware abusing native security tools, and defenders should monitor BitLocker changes closely.

First seen
May 2024
Last seen
October 2026

21 techniques across 7 tactics.

TA0002 Execution

TA0005 Stealth

TA0007 Discovery

  • T1016System Network Configuration Discovery
  • T1057Process Discovery
  • T1082System Information Discovery
  • T1124System Time Discovery

TA0011 Command and Control

TA0010 Exfiltration

  • T1041Exfiltration Over C2 Channel

TA0040 Impact

TA0112 Defense Impairment

Alert Name
Dump:Generic.VBS.ShrinkLocker.B.FFFFFFFE
Generic.VBS.ShrinkLocker.A.07D2AC86
Generic.VBS.ShrinkLocker.A.09099AC9
Generic.VBS.ShrinkLocker.A.1622CAC4
Generic.VBS.ShrinkLocker.A.1D47F9F4
Generic.VBS.ShrinkLocker.A.1D8BF9D8
Generic.VBS.ShrinkLocker.A.23820C7D
Generic.VBS.ShrinkLocker.A.382B3344
Generic.VBS.ShrinkLocker.A.3EA36EC4
Generic.VBS.ShrinkLocker.A.420C7792