Researchers reported that ShrinkLocker is a ransomware strain that turns Microsoft BitLocker against victims by modifying disk layouts, boot settings, and recovery mechanisms instead of relying only on conventional file encryption. Splunk said the malware checks the operating system, changes registry settings related to RDP and TPM, disables BitLocker key protectors, shrinks non-boot partitions, formats them, and rewrites boot configuration in ways that can leave affected machines difficult or impossible to recover. The malware was also observed exfiltrating data to command-and-control infrastructure and attempting to erase evidence by deleting logs, firewall rules, and scheduled tasks.
Public reporting tied the activity to malware components including disk.vbs_, Dim oShell.txt, and run.vbs, highlighting a script-driven intrusion chain built around native Windows functionality. Bitdefender later published a ShrinkLocker decryptor, framing the threat as a case in which a legitimate Microsoft disk-encryption feature was repurposed for ransomware and then countered with a recovery tool. The combined reporting underscores that ShrinkLocker can both deny access to systems and complicate restoration by corrupting partitions and boot paths while using BitLocker as the locking mechanism.

Pull IOCs and campaign context straight into your stack.
2 events from the most recent confirmed update back to the earliest known activity.
Bitdefender published research titled "ShrinkLocker (+Decryptor): From Friend to Foe, and Back Again," indicating the release or public availability of a decryptor for ShrinkLocker victims. The publication marks a defensive response following disclosure of the ransomware's BitLocker-based attack method.
Splunk reported a newly discovered ransomware strain named ShrinkLocker that abuses Microsoft BitLocker and modifies the boot environment to lock victims out of their systems. The report described behavior including OS checks, registry changes affecting RDP and TPM, disabling BitLocker key protectors, shrinking and formatting partitions, data exfiltration, and log and task deletion.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.