* . *
  • About
  • Advertise
  • Privacy & Policy
  • Contact
Wednesday, August 13, 2025
Earth-News
  • Home
  • Business
  • Entertainment
    JPMorgan raises Flutter Entertainment stock price target to GBP273 – Investing.com

    JPMorgan Raises Flutter Entertainment Price Target to £273, Signaling Strong Growth Ahead

    Star Entertainment reaches deal to sell 50% stake in Brisbane resort to HK investors – Reuters

    Star Entertainment Seals Landmark Deal, Sells Half of Brisbane Resort to Hong Kong Investors

    Country music star ripped by ex-wife amid court battle: ‘Karma is a … well you know’ – PennLive.com

    This LA singer performed at Trump casinos. Now he’s a retired bus driver in Acadiana. – The Advocate

    This LA singer performed at Trump casinos. Now he’s a retired bus driver in Acadiana. – The Advocate

    Six Flags Entertainment Corporation Reports 2025 Second Quarter Results, Provides July Performance Update, and Updates Full-Year Guidance – Business Wire

    Six Flags Reveals Thrilling Q2 2025 Results, Shares July Highlights, and Updates Full-Year Outlook

    ‘Paying homage to Kansas’: Singer-songwriter Dallas Pryor shares music journey – The Topeka Capital-Journal

    Honoring Kansas: Singer-Songwriter Dallas Pryor Shares His Inspiring Musical Journey

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    California’s wildfire moonshot: How new technology will defeat advancing flames – Los Angeles Times

    California’s Wildfire Revolution: How Cutting-Edge Technology Is Poised to Stop Raging Flames

    LSU grad uses 3D printing to create adaptive technology for children – CBS News

    LSU Graduate Revolutionizes Adaptive Technology for Kids with 3D Printing

    Gas-to-liquids technology can support national resilience – The Strategist | ASPI’s analysis and commentary site

    Unlocking National Strength: How Gas-to-Liquids Technology Drives Resilience

    Micron Technology (MU) Launched a New Memory Chip for Space Application – Yahoo Finance

    Micron Technology Launches Revolutionary Memory Chip Built for Space Exploration

    United Airlines passengers in US delayed after tech glitch halts flights – BBC

    United Airlines passengers in US delayed after tech glitch halts flights – BBC

    Preparing Students for the Technology of Tomorrow – Drug Topics

    Preparing Students Today to Thrive in Tomorrow’s Tech-Driven World

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
  • Home
  • Business
  • Entertainment
    JPMorgan raises Flutter Entertainment stock price target to GBP273 – Investing.com

    JPMorgan Raises Flutter Entertainment Price Target to £273, Signaling Strong Growth Ahead

    Star Entertainment reaches deal to sell 50% stake in Brisbane resort to HK investors – Reuters

    Star Entertainment Seals Landmark Deal, Sells Half of Brisbane Resort to Hong Kong Investors

    Country music star ripped by ex-wife amid court battle: ‘Karma is a … well you know’ – PennLive.com

    This LA singer performed at Trump casinos. Now he’s a retired bus driver in Acadiana. – The Advocate

    This LA singer performed at Trump casinos. Now he’s a retired bus driver in Acadiana. – The Advocate

    Six Flags Entertainment Corporation Reports 2025 Second Quarter Results, Provides July Performance Update, and Updates Full-Year Guidance – Business Wire

    Six Flags Reveals Thrilling Q2 2025 Results, Shares July Highlights, and Updates Full-Year Outlook

    ‘Paying homage to Kansas’: Singer-songwriter Dallas Pryor shares music journey – The Topeka Capital-Journal

    Honoring Kansas: Singer-Songwriter Dallas Pryor Shares His Inspiring Musical Journey

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    California’s wildfire moonshot: How new technology will defeat advancing flames – Los Angeles Times

    California’s Wildfire Revolution: How Cutting-Edge Technology Is Poised to Stop Raging Flames

    LSU grad uses 3D printing to create adaptive technology for children – CBS News

    LSU Graduate Revolutionizes Adaptive Technology for Kids with 3D Printing

    Gas-to-liquids technology can support national resilience – The Strategist | ASPI’s analysis and commentary site

    Unlocking National Strength: How Gas-to-Liquids Technology Drives Resilience

    Micron Technology (MU) Launched a New Memory Chip for Space Application – Yahoo Finance

    Micron Technology Launches Revolutionary Memory Chip Built for Space Exploration

    United Airlines passengers in US delayed after tech glitch halts flights – BBC

    United Airlines passengers in US delayed after tech glitch halts flights – BBC

    Preparing Students for the Technology of Tomorrow – Drug Topics

    Preparing Students Today to Thrive in Tomorrow’s Tech-Driven World

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
Earth-News
No Result
View All Result
Home Technology

Here’s yet more ransomware using BitLocker against Microsoft’s own users

May 23, 2024
in Technology
Here’s yet more ransomware using BitLocker against Microsoft’s own users
Share on FacebookShare on Twitter

Yet more ransomware is using Microsoft BitLocker to encrypt corporate files, steal the decryption key, and then extort a payment from victim organizations, according to Kaspersky.

The antivirus maker’s Global Emergency Response team spotted the malware, dubbed ShrinkLocker, in Mexico, Indonesia, and Jordan, and said the code’s unnamed operators targeted steel and vaccine manufacturing companies, plus a government entity.

Criminals, including ransomware gangs, using legitimate software tools is nothing new — hello, Cobalt Strike. And, in fact, Microsoft previously said Iranian miscreants had abused Windows’ built-in BitLocker full-volume encryption feature to lock up compromised devices. We can recall other strains of extortionware using BitLocker on infected machines to encrypt data and hold it to ransom.

With ShrinkLocker, however, “the adversary took additional steps to maximize the damage from the attack and hinder an effective response to the incident,” Kasperky threat hunters Cristian Souza, Eduardo Ovalle, Ashley Muñoz, and Christopher Zachor said in research published Thursday. The write-up includes technical details for detecting and blocking ShrinkLocker variants.

The Register has reached out to Redmond for comment, and will update this story if and when we hear back.

sad IT pro at computer

Ransomware attacks hospitalizing security pros, as one admits suicidal feelings

READ MORE

Once they’ve got code execution on a victim’s machine, the data thieves deploy ShrinkLocker, which uses VBScript to probe Windows Management Instrumentation to determine the operating system version. It does this so that it selects the correct steps for whichever Microsoft OS is running, allowing it to extort current systems as well as those dating back to Windows Server 2008.

As for those steps, the script performs disk resizing operations (this is the “Shrink” part of ShrinkLocker) on fixed rather than network drives (presumably to minimize detection), rejigs the partitioning and boot setup, ensures BitLocker is up and running, and ultimately encrypts the computer’s storage. See the Kaspersky report for how that works specifically for each flavor of Microsoft’s operating systems.

Additionally, the malware changes the label of partitions to the extortionists’ email, which allows the victim to contact the crooks.

After sending the decryption key needed to access the scrambled drives to a server controlled by the criminals, the malware deletes the key locally, trashing the user’s recovery options, along with system logs that may help network defenders more easily spot or analyze the attack.

Finally, it shuts down the compromised system and displays the BitLocker screen with a message: “There are no more BitLocker recovery options on your PC.” Game over.

Windows users left to fend for themselves after BitLocker patch bungle

Crims abusing Microsoft Quick Assist to deploy Black Basta ransomware

Researchers claim Windows Defender can be fooled into deleting databases

Microsoft slammed for lax security that led to China’s cyber-raid on Exchange Online

In addition to listing ShrinkLocker’s indicators of compromise, and suggesting organizations use managed detection and response products to look for threats, cough, Kaspersky recommends businesses take steps to avoid falling victim to these ransomware infections.

This includes limiting user privileges so they can’t enable encryption features or modify registry keys. And if you do have BitLocker enabled, use a strong password and store recovery keys securely.

Also, monitor for VBScript and PowerShell execution events, and log as much critical system activity as possible to an external repository that can’t be deleted locally.

Plus backup systems and files frequently, store them offline, and make sure to test them to ensure they can be recovered in the event of ransomware or some other security snafu. ®

PS: Still feeling good about that Windows Recall and its encrypted snapshots?

>>> Read full article>>>
Copyright for syndicated content belongs to the linked Source : The Register – https://go.theregister.com/feed/www.theregister.com/2024/05/23/ransomware_abuses_microsoft_bitlocker/

Tags: Here’sRansomwaretechnology
Previous Post

Microsoft’s deal with UAE’s G42 sparks fears over true destination of AI exports

Next Post

California Bill Would Require New Cars to Beep at You If You Speed

2025 World Games Features Gator Softball Trio – Florida Gators

2025 World Games Features Gator Softball Trio – Florida Gators

August 12, 2025
Shutting down the economy won’t help the hostages – JNS.org

Shutting down the economy won’t help the hostages – JNS.org

August 12, 2025
JPMorgan raises Flutter Entertainment stock price target to GBP273 – Investing.com

JPMorgan Raises Flutter Entertainment Price Target to £273, Signaling Strong Growth Ahead

August 12, 2025
Heart Surgery – UT Health East Texas

Heart Surgery – UT Health East Texas

August 12, 2025
Big Tech’s next major political battle may already be brewing in your backyard – Politico

The Next Big Political Battle for Tech Giants Is About to Begin

August 12, 2025
Applying ecological principles to microbiome engineering – Nature

Applying ecological principles to microbiome engineering – Nature

August 12, 2025
What is Pain? Explore the science and the radical new paths for relief – cosmosmagazine.com

What Is Pain? Discover the Science Behind It and Explore Breakthrough Paths to Lasting Relief

August 12, 2025
Why do cats and dogs eat grass? – Live Science

Why Do Cats and Dogs Munch on Grass? Uncover the Surprising Reasons Behind This Curious Habit!

August 12, 2025
Healthy Lifestyle Can Help People at Risk for Dementia, Study Finds – The New York Times

Healthy Lifestyle Can Help People at Risk for Dementia, Study Finds – The New York Times

August 12, 2025
California’s wildfire moonshot: How new technology will defeat advancing flames – Los Angeles Times

California’s Wildfire Revolution: How Cutting-Edge Technology Is Poised to Stop Raging Flames

August 12, 2025

Categories

Archives

August 2025
MTWTFSS
 123
45678910
11121314151617
18192021222324
25262728293031
« Jul    
Earth-News.info

The Earth News is an independent English-language daily published Website from all around the World News

Browse by Category

  • Business (20,132)
  • Ecology (767)
  • Economy (790)
  • Entertainment (21,667)
  • General (16,429)
  • Health (9,829)
  • Lifestyle (800)
  • News (22,149)
  • People (791)
  • Politics (799)
  • Science (16,003)
  • Sports (21,287)
  • Technology (15,770)
  • World (773)

Recent News

2025 World Games Features Gator Softball Trio – Florida Gators

2025 World Games Features Gator Softball Trio – Florida Gators

August 12, 2025
Shutting down the economy won’t help the hostages – JNS.org

Shutting down the economy won’t help the hostages – JNS.org

August 12, 2025
  • About
  • Advertise
  • Privacy & Policy
  • Contact

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

Go to mobile version