Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
A new attack tool named “BitUnlocker” targeting BitLocker encryption on Windows 11 systems has been identified.
"CVE-2025-26637 and tools like BitUnlocker show how these vectors are being actively explored."
13 distinct techniques documented for this family, organized by ATT&CK tactic.
The attack proceeds as follows: the attacker prepares a modified BCD (Boot Configuration Data) file pointing to a tampered SDI and serves an old, vulnerable PCA 2011-signed boot manager via USB or PXE boot.
According to Intrinsec, the attacker requires only physical access to the target workstation, a USB drive or PXE boot server... and serves an old, vulnerable PCA 2011-signed boot manager via USB or PXE boot.
When the boot manager loads a legitimate WIM file referenced by an SDI for integrity verification, it simultaneously allows a second, attacker-controlled WIM to be appended to the SDI’s blob table. The boot manager verifies the first (legitimate) WIM but actually boots from the second, which contains a WinRE image modified to launch cmd.exe with the BitLocker volume already decrypted and mounted.
Direct Volume Access (T1006) - чтение содержимого расшифрованного тома
CVE-2025-48804 эксплуатирует первое и второе изменения. CWE-349 ... атакующий подаёт boot manager легитимный WIM-файл для прохождения проверки целостности, но присоединяет вредоносную нагрузку. Система верифицирует чистую часть - и слепо запускает код атакующего.
When the boot manager loads a legitimate WIM file referenced by an SDI for integrity verification, it simultaneously allows a second, attacker-controlled WIM to be appended to the SDI’s blob table. The boot manager verifies the first (legitimate) WIM but actually boots from the second, which contains a WinRE image modified to launch cmd.exe with the BitLocker volume already decrypted and mounted.
The critical weakness enabling the BitUnlocker attack is not a missing patch it is an unrevoked signing certificate. Secure Boot validates a binary’s signing certificate, not its version number. The legacy Microsoft Windows PCA 2011 certificate... remains trusted... This means a pre-patch bootmgfw.efi, signed under PCA 2011, is still considered completely valid by Secure Boot despite being vulnerable.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An attack tool that performs a practical downgrade attack against BitLocker on Windows 11, abusing WinRE/SDI boot behavior to launch a modified recovery image and access a BitLocker-protected volume after it has been decrypted and mounted. The attack requires physical access and is especially effective against TPM-only BitLocker configurations.
A proof-of-concept tool that performs a downgrade attack against BitLocker by booting a vulnerable pre-patch Microsoft boot manager signed with a still-trusted certificate, enabling decryption and mounting of BitLocker-protected volumes on affected systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.