HomeSecurityShrinkLocker ransomware: Free decryption tool

ShrinkLocker ransomware: Free decryption tool

Cybersecurity company Bitdefender has released a free decryption tool for the ShrinkLocker ransomwareto help victims recover their data without paying a ransom to hackers.

ShrinkLocker ransomware decryption

Researchers analyzed the inner workings of ShrinkLocker and managed to create the decryption tool.

ShrinkLocker was first documented in May 2024 by Kaspersky. The company then observed that the ransomware BitLocker Microsoft's to encrypt files in attacks against Mexico, Indonesia, and Jordan.

Bitdefender, which investigated a ShrinkLocker ransomware attack on a healthcare company in the Middle East, said the attack likely originated from a machine belonging to a contractor. This shows once again how cybercriminals are abusing relationships of trust to infiltrate the supply chain.

See also: Halliburton: $35 million in losses after ransomware attack

In the next stage, the attackers moved to an Active Directory domain controller, using legitimate credentials for a compromised account. Then, two scheduled tasks were created to trigger the ransomware process.

According to Bitdefender, the ShrinkLocker ransomware successfully encrypted systems running Windows 10, Windows 11, Windows Server 2016, and Windows Server 2019.

The ransomware's modus operandi is simple but effective. The malware is written in VBScript and instead of implementing its own encryption algorithm, it leverages BitLocker to achieve its goals.

The script is designed to collect information about the system configuration and operating system. It attempts to check if BitLocker is already installed on a Windows Server computer and, if not, installs it using a PowerShell command. It then performs a “forced restart” using Win32Shutdown.

However, Bitdefender researchers have identified a bug that causes this request to fail with a “Privilege Not Held” error.

See also: New Ymir ransomware collaborates with RustyStealer in attacks

“Even if the server is restarted manually (e.g. by an unsuspecting administrator), the script has no mechanism to continue its execution after the restart, which means the attack can be interrupted or prevented,” said Martin Zugec, technical solutions manager at Bitdefender.

ShrinkLocker ransomware is designed to generate a random password, derived from specific system information, such as network traffic, system memory, and disk usage, and uses it to encrypt system drives.

The unique password is uploaded to a server controlled by the attacker. After rebooting, the user is prompted to enter the password to unlock the encrypted drive. The BitLocker screen is also configured to display the threat, to initiate payment in exchange for the password.

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Additionally, the script makes several registry modifications to restrict access to the system and disables remote RDP and local connections. It also disables Windows Firewall rules and deletes audit files.

Ransomware protection

Back up your data: One of the most effective ways to protect yourself from a  attack  is to regularly back up your data. This ensures that even if your data is encrypted by ransomware, you will have a safe copy that can be restored without paying the ransom.

Update your operating system and software: Out-of-date operating systems and software are vulnerable to cyberattacks. It is important to regularly update your devices with the latest  security  and software updates to prevent any vulnerabilities that could be exploited by ransomware.

See also: Frag ransomware: Exploits Veeam vulnerability in attacks

ShrinkLocker ransomware: Free decryption tool
ShrinkLocker ransomware: Free decryption tool

Beware of suspicious emails and links: Ransomware attacks often start with a phishing email or malicious link. It is important to be cautious when opening emails from unknown senders. Also, do not click on suspicious links. These could lead to ransomware being installed on your device.

Use antivirus software:  Installing reputable antivirus software on your devices can help you detect and prevent attacks  . Be sure to update your antivirus software to ensure it is equipped to handle new threats.

Education: One of the most important steps to protect against ransomware is education. It is important to stay up to date on the latest types of ransomware and how they work. Organizations should also train their employees on how to identify and avoid potential attacks.

Implement strong passwords: Weak or easy passwords can make it easier for hackers to gain access to your devices and install ransomware. It's important to use strong and unique passwords and enable two-factor authentication whenever possible.

Use a VPN: A VPN encrypts your internet connection and provides an extra layer of security against ransomware attacks. This is especially important when using public Wi-Fi networks, which are often unsecured and vulnerable to attacks.

Source: thehackernews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS