Security researcher Kim Dvash disclosed GhostLock, a proof-of-concept tool that abuses the legitimate Windows CreateFileW API to deny access to files on local systems and SMB network shares without encrypting or deleting data. By opening files with dwShareMode set to 0, the tool obtains exclusive handles that cause other users and applications to receive STATUS_SHARING_VIOLATION errors while the handles remain open, effectively creating a file-level denial-of-service condition.
Reports say GhostLock can recursively lock large numbers of files on network shares, can be run by standard domain users without elevated privileges, and could be amplified from multiple compromised endpoints to increase disruption. Researchers warned the technique may evade many security products because it relies on legitimate file-open operations rather than ransomware-style writes or encryption, and said it could also be used as a diversion during intrusions while attackers pursue data theft or lateral movement; recommended detection focuses on unusually high per-session open-file counts and ShareAccess = 0 visibility at the file server layer, supported by published SIEM queries and an NDR detection rule.

Get the actors, campaigns, and ATT&CK mapping behind it.
2 events from the most recent confirmed update back to the earliest known activity.
Dvash published a GhostLock whitepaper with SIEM queries and an NDR detection rule to help defenders identify the behavior, emphasizing monitoring high per-session open-file counts with ShareAccess = 0 at the file server layer. The guidance noted that many security tools may miss the activity because it relies on legitimate file-open operations rather than encryption or mass file writes.
Security researcher Kim Dvash of Israel Aerospace Industries released GhostLock, a proof-of-concept tool that abuses the legitimate Windows CreateFileW API with dwShareMode set to 0 to deny access to local and SMB-shared files. The technique allows even standard domain users without elevated privileges to recursively lock many files and trigger STATUS_SHARING_VIOLATION errors for other users and applications.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.