BitLocker is Microsoft's legitimate Windows volume-encryption feature, not a malware family. Threat actors abuse it as a post-compromise encryption mechanism in ransomware and extortion operations, denying victims access to disks without deploying a purpose-built ransomware encryptor. Observed attacks configure encryption through native Windows utilities or scripts and forcibly lock or dismount encrypted volumes, leaving victims dependent on attacker-configured credentials or recovery material. Ransom notes demand payment for restoration of access.
BitLocker abuse has been associated with Iranian actors including COBALT MIRAGE and DEV-0270, as well as APT35 and the China-linked APT41. DPRK state-sponsored actors have also been observed using or possessing the tool. In documented intrusions, attackers compromised exposed IIS or Microsoft Exchange servers, escalated privileges, established remote access, and subsequently enabled BitLocker on victim systems. Some operations used BitLocker on servers alongside DiskCryptor on workstations.
Affected environments include Windows servers and workstations across multiple industries and regions. Documented victims include Korean businesses and Romania's national water administration, where approximately 1,000 IT systems were affected while operational technology remained unaffected. BitLocker provides the encryption component of these attacks; initial access, credential theft, lateral movement, and remote access are performed through separate exploits and tools.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
APT35 primarily conducts cyber espionage using spearphishing, social engineering, and custom malware techniques; however, it has also exploited Microsoft BitLocker to encrypt targets’ data in exchange for ransom payments.
Last week, Microsoft took the wraps off a string of ransomware attacks mounted by a Phosphorus subgroup dubbed DEV-0270 using living-off-the-land binaries such as BitLocker.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
These were used to deploy scheduled tasks responsible for enabling the BitLocker service and individually encrypting the infrastructure’s disks...
These were used to deploy scheduled tasks responsible for enabling the BitLocker service and individually encrypting the infrastructure’s disks, generating a key for each encrypted system.
push the BitLocker GPO configuration across the domain alongside logon or start scripts containing the appropriate command line or PowerShell commands
These were used to deploy scheduled tasks responsible for enabling the BitLocker service and individually encrypting the infrastructure’s disks...
push the BitLocker GPO configuration across the domain alongside logon or start scripts containing the appropriate command line or PowerShell commands
These were used to deploy scheduled tasks responsible for enabling the BitLocker service and individually encrypting the infrastructure’s disks...
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
BitLocker, a native Windows disk encryption tool, is being abused by threat actors to encrypt victim systems and demand ransom, effectively turning it into a ransomware tool.
BitLocker is a legitimate Windows disk encryption feature that has been abused by threat actors to encrypt files on compromised systems and demand ransom, effectively turning it into a ransomware tool.
Legitimate Microsoft encryption software explicitly described as abused by APT35 to encrypt victim data for ransom. Included because of its stated malicious use, not because BitLocker is inherently malware. No trojanized version or associated named ransomware family is identified.
A legitimate disk encryption tool abused in attack clusters as an encryption mechanism affecting multiple industries across North America, South America, and Europe.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.