ShrinkLocker Turning BitLocker into ransomware

The attackers were able to deploy and run an advanced VBS script that took advantage of BitLocker for unauthorized file encryption. We spotted this script and its modified versions in Mexico Indonesia and Jordan. In the sections below we analyze in detail the malicious code obtained during our incident response effort and provide tips for mitigating this kind of threat.