BitLocker is Microsoft’s native full-disk encryption feature for Windows and Windows Server. Although it is a legitimate security product rather than a malware family, it has repeatedly been abused by threat actors as an encryption mechanism in ransomware and disruptive intrusion operations. Adversaries use BitLocker after obtaining administrative control of Windows environments to encrypt workstations or servers, impair availability, and present ransom demands while reducing the need to deploy custom encryptor malware.
BitLocker abuse has been documented in financially motivated and state-linked operations. Iranian clusters tracked as PHOSPHORUS, DEV-0270, and COBALT MIRAGE have used BitLocker in ransomware-style attacks, including campaigns following exploitation of Microsoft Exchange ProxyShell and other internet-facing vulnerabilities. APT41 has also been reported using BitLocker to encrypt workstations, and multiple investigations have noted unattributed or loosely attributed attack clusters using BitLocker alongside other off-the-shelf encryption tools such as DiskCryptor and BestCrypt. DPRK-linked ransomware operators have likewise been observed possessing or using publicly available encryption tools including BitLocker.
Operationally, attackers typically abuse BitLocker only after compromise and privilege escalation, often as part of rapid hands-on-keyboard intrusions involving web shells, remote administration utilities, credential access, lateral movement, and domain-wide impact. Reported victimology spans government, healthcare, critical infrastructure, and private-sector organizations across North America, South America, Europe, Israel, Australia, and elsewhere. Because BitLocker is built into Windows, its malicious use can complicate detection and attribution by blending destructive or extortion activity with legitimate system functionality.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Last week, Microsoft took the wraps off a string of ransomware attacks mounted by a Phosphorus subgroup dubbed DEV-0270 using living-off-the-land binaries such as BitLocker.
Last week, Microsoft took the wraps off a string of ransomware attacks mounted by a Phosphorus subgroup dubbed DEV-0270 using living-off-the-land binaries such as BitLocker.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
These were used to deploy scheduled tasks responsible for enabling the BitLocker service and individually encrypting the infrastructure’s disks...
These were used to deploy scheduled tasks responsible for enabling the BitLocker service and individually encrypting the infrastructure’s disks, generating a key for each encrypted system.
push the BitLocker GPO configuration across the domain alongside logon or start scripts containing the appropriate command line or PowerShell commands
These were used to deploy scheduled tasks responsible for enabling the BitLocker service and individually encrypting the infrastructure’s disks...
push the BitLocker GPO configuration across the domain alongside logon or start scripts containing the appropriate command line or PowerShell commands
These were used to deploy scheduled tasks responsible for enabling the BitLocker service and individually encrypting the infrastructure’s disks...
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
BitLocker, a native Windows disk encryption tool, is being abused by threat actors to encrypt victim systems and demand ransom, effectively turning it into a ransomware tool.
BitLocker is a legitimate Windows disk encryption feature that has been abused by threat actors to encrypt files on compromised systems and demand ransom, effectively turning it into a ransomware tool.
A legitimate disk encryption tool abused in attack clusters as an encryption mechanism affecting multiple industries across North America, South America, and Europe.
Legitimate Windows full-disk encryption feature abused by threat actors to encrypt victim systems as part of ransomware-style attacks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.