ShrinkLocker is a Windows ransomware strain that abuses Microsoft BitLocker and native system utilities to deny access to victim systems rather than relying solely on a conventional custom file-encryption routine. It has been described as a VBScript-based threat that validates aspects of the target environment before proceeding, then manipulates disk layout, boot configuration, and BitLocker policy settings to maximize disruption and complicate recovery. Observed behavior includes shrinking non-boot partitions, creating new boot volumes, reinstalling or reconfiguring boot files, enabling BitLocker even on systems without TPM support, and deleting BitLocker protectors so victims are left without normal recovery options. Some reporting also notes that these partition and boot changes can destabilize systems and may cause data corruption or render hosts difficult to recover.
ShrinkLocker modifies Windows registry settings associated with BitLocker configuration and has also been observed changing settings related to Remote Desktop. It uses legitimate Windows components such as disk management tooling, BCDEdit, WMI, and BitLocker administration commands as part of a living-off-the-land approach. After encryption activity, it can forcibly shut down the system, and it may restart the host if execution errors occur. Defense-evasion behavior attributed to the malware includes deleting logs, scheduled tasks, and firewall rules.
Unlike many ransomware families, ShrinkLocker has been reported to avoid a traditional ransom note on disk. Instead, it can rename disk labels to embed attacker contact information for ransom negotiation. It also exfiltrates victim system information and the generated BitLocker key to attacker-controlled infrastructure, including use of Cloudflare Tunnel services to obscure the receiving endpoint.
Victimology reported for ShrinkLocker includes a government entity and organizations in the vaccine, steel, and manufacturing sectors, with observed targeting in Mexico, Indonesia, and Jordan. The malware is associated with corporate Windows environments and stands out for combining extortion with strongly destructive characteristics, leading some researchers to assess that certain deployments may be intended to cause operational damage as much as to obtain payment.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
Examples include "DarkTortilla can obtain system information by querying the Win32_ComputerSystem, Win32_BIOS, Win32_MotherboardDevice, Win32_PnPEntity, and Win32_DiskDrive WMI objects" and "Kimsuky has also obtained system information ... through querying various Windows Management Instrumentation (WMI) classes including Win32_OperatingSystem."
and attempts to erase traces of its activity by deleting logs, firewall rules, and scheduled tasks.
The content repeatedly describes adversaries and malware deleting files, directories, droppers, scripts, logs, archives, staged data, and other artifacts from compromised systems, e.g., 'APT29 has used SDelete to remove artifacts from victim networks' and 'Lazarus Group malware has deleted files in various ways, including "suicide scripts" to delete malware binaries from the victim.'
The content repeatedly describes malware and threat actors obtaining lists of running processes, using utilities such as tasklist, ps, WMI, Get-Process, CreateToolhelp32Snapshot, EnumProcesses, and similar APIs/commands to enumerate active processes on victim systems.
The content repeatedly describes malware and threat actors collecting host details such as OS version, hostname, architecture, CPU, memory, BIOS, domain, language, and other configuration data; e.g., "APT41 uses multiple built-in commands such as systeminfo and net config Workstation to enumerate victim system basic configuration information."
ADVSTORESHELL exfiltrates data over the same channel used for C2... Agrius exfiltrated staged data using tools such as Putty and WinSCP, communicating with command and control servers... numerous malware and groups sent victim data, files, credentials, or host information over existing C2 channels.
“Sandworm Team deployed CaddyWiper…to wipe files…along with mapped drives, and physical drive partitions… AcidPour…perform an in-depth wipe…through either data overwrite or calling various IOCTLS… AcidRain performs an in-depth wipe… Apostle…data destruction tool… writes random data… resizing… deleting… BlackEnergy 2 contains a ‘Destroy’ plug-in… overwriting file contents… HermeticWiper… recursively wipe folders and files… Industroyer’s data wiper module clears registry keys and overwrites… KillDisk deletes system files to make the OS unbootable… Shamoon attempts to overwrite operating system files and disk structures… WhisperGate… corrupt files by overwriting…”
диски были зашифрованы с помощью BitLocker... Чтобы разблокировать такие диски, нужен ключ восстановления
MultiLayer Wiper 'removes the Volume Shadow Copy (VSS) service from infected devices along with all present shadow copies'; ShrinkLocker 'disables protectors used to secure the BitLocker encryption key on victim systems.'
"AcidPour includes functionality to reboot the victim system following wiping actions..."; "AcidRain reboots the target system once the various wiping processes are complete"; "Apostle reboots the victim machine following wiping"; "APT37 ... issue the command shutdown /r /t 1 to reboot a system after wiping its MBR"; "APT38 ... BOOTWRECK ... initiate a system reboot after wiping the victim's MBR"; "Black Basta ... used ShellExecuteA to shut down and restart"; "DarkGate ... used the shutdown command"; "HermeticWiper can initiate a system shutdown"; "NotPetya will reboot the system one hour after infection"; "Shamoon will reboot the infected system once the wiping functionality has been completed"; "WhisperGate can shutdown ... through ... ExitWindowsEx"
After disabling BitLocker key protectors, ShrinkLocker shrinks non-boot partitions by 100MB, formats these partitions, and reconfigures boot files to destabilize the system, potentially rendering it irreparable.
The content repeatedly describes threat actors and malware disabling or modifying security tools, EDR/AV, logging, firewall rules, integrity checkers, and security settings; e.g., 'Agrius used several mechanisms to try to disable security tools' and 'BlackByte disabled security tools such as Windows Defender and the Raccine anti-ransomware tool during operations.'
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
29 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named threat previously discovered by the researchers that abuses BitLocker to encrypt data for extortion.
Malware previously identified by the researchers that encrypts data by abusing BitLocker.
Ransomware family referenced in the associated analytic stories.
Referenced as malware in associated analytic story listings; commonly a ransomware/extortion-related family, but no further detail is given in the text.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.