{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/actors/shrinklocker/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":["ShrinkLocker"],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Windows"],"_cs_severities":["high"],"_cs_tags":["ransomware","defense-evasion","registry-tampering"],"_cs_type":"threat","_cs_vendors":["Microsoft"],"content_html":"\u003cp\u003eShrinkLocker is a ransomware strain that abuses the native BitLocker Drive Encryption (BDE) functionality to lock victim systems. Rather than relying solely on external encryption tools, the malware manipulates Windows Registry keys under \u003ccode\u003eHKLM\\Software\\Policies\\Microsoft\\FVE\\\u003c/code\u003e to reconfigure how the operating system handles disk encryption. By programmatically modifying these policies, ShrinkLocker can bypass TPM requirements, force the creation of partial encryption keys, or enforce specific PIN-based startup configurations. This approach allows the actor to weaponize built-in system security features against the host, effectively locking the system and demanding a ransom. Defenders must monitor for unauthorized modifications to these sensitive security registry paths to detect early-stage tampering before the encryption process completes.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe malware gains initial access to the Windows host through a spearphishing attachment or drive-by download.\u003c/li\u003e\n\u003cli\u003eThe process elevates privileges to administrative levels to perform system-wide registry modifications.\u003c/li\u003e\n\u003cli\u003eThe malware queries the \u003ccode\u003eHKLM\\Software\\Policies\\Microsoft\\FVE\\\u003c/code\u003e registry path to check current encryption policies.\u003c/li\u003e\n\u003cli\u003eThe process executes registry writes to set \u003ccode\u003eEnableBDEWithNoTPM\u003c/code\u003e or \u003ccode\u003eEnableNonTPM\u003c/code\u003e to \u003ccode\u003e1\u003c/code\u003e, lowering the barrier for BitLocker deployment.\u003c/li\u003e\n\u003cli\u003eThe malware further enforces configurations by setting values such as \u003ccode\u003eUsePIN\u003c/code\u003e or \u003ccode\u003eUseTPMPIN\u003c/code\u003e to \u003ccode\u003e2\u003c/code\u003e to dictate the encryption unlocking mechanism.\u003c/li\u003e\n\u003cli\u003eShrinkLocker triggers the built-in \u003ccode\u003emanage-bde.exe\u003c/code\u003e utility or the underlying BitLocker API to initiate disk encryption using the newly applied policy constraints.\u003c/li\u003e\n\u003cli\u003eThe system is rebooted or encryption finishes, resulting in a locked machine requiring the attacker-defined key or PIN to access files.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful deployment of ShrinkLocker leads to the complete encryption of enterprise data via native Windows features. This technique causes significant operational downtime, as it prevents legitimate system access and renders local data inaccessible without the actor-controlled key. The ransomware has been observed targeting various Windows environments, and the nature of the encryption makes recovery difficult without established backups or the specific keys generated during the tampering process.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eDeploy the Sigma rules below to monitor for unauthorized modifications to BitLocker registry keys; focus on any process (other than authorized management tools) attempting to set \u003ccode\u003eFVE\u003c/code\u003e policy values.\u003c/li\u003e\n\u003cli\u003eImplement registry auditing (Sysmon Event ID 13) specifically for the \u003ccode\u003eHKLM\\Software\\Policies\\Microsoft\\FVE\\\u003c/code\u003e registry tree.\u003c/li\u003e\n\u003cli\u003eRestrict administrative rights to ensure only authorized IT management software can modify system-wide encryption policies.\u003c/li\u003e\n\u003cli\u003eMonitor for the execution of \u003ccode\u003emanage-bde.exe\u003c/code\u003e by processes not associated with standard system administration tasks.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-08-17T18:37:23Z","date_published":"2026-08-17T18:37:23Z","id":"https://feed.craftedsignal.io/briefs/2026-08-shrinklocker-bitlocker-tampering/","summary":"The ShrinkLocker ransomware actor exploits native Windows registry configurations to manipulate BitLocker encryption behavior, bypassing security requirements to facilitate unauthorized data encryption.","title":"ShrinkLocker Ransomware BitLocker Registry Tampering","url":"https://feed.craftedsignal.io/briefs/2026-08-shrinklocker-bitlocker-tampering/"}],"language":"en","title":"CraftedSignal Threat Feed - ShrinkLocker","version":"https://jsonfeed.org/version/1.1"}