{"id":234,"date":"2024-06-18T20:19:46","date_gmt":"2024-06-18T18:19:46","guid":{"rendered":"https:\/\/www.diskigo.com\/blog\/?p=234"},"modified":"2024-06-18T20:30:19","modified_gmt":"2024-06-18T18:30:19","slug":"shrinklocker-le-nouveau-ransomware-qui-cible-les-pc-windows","status":"publish","type":"post","link":"https:\/\/www.diskigo.com\/blog\/shrinklocker-le-nouveau-ransomware-qui-cible-les-pc-windows\/","title":{"rendered":"ShrinkLocker, le nouveau ransomware qui cible les PC Windows"},"content":{"rendered":"<h2>Nouveau Ransomware ShrinkLocker : Une menace inqui\u00e9tante pour les utilisateurs Windows<\/h2>\n<p><a href=\"https:\/\/securelist.com\/ransomware-abuses-bitlocker\/112643\/\">Les experts de Kaspersky<\/a> ont d\u00e9couvert un nouveau ransomware, nomm\u00e9 <em>ShrinkLocker<\/em>, qui cible sp\u00e9cifiquement les ordinateurs sous Windows. Ce malware exploite BitLocker, le module de chiffrement int\u00e9gr\u00e9 par Microsoft, pour passer inaper\u00e7u.<\/p>\n<p><em>BitLocker<\/em>, introduit en 2007 avec Windows Vista, permet aux utilisateurs de prot\u00e9ger leurs donn\u00e9es en chiffrant enti\u00e8rement le disque dur. Cependant, ShrinkLocker d\u00e9tourne cette fonctionnalit\u00e9 \u00e0 des fins malveillantes. Selon Kaspersky, \u00ab utiliser les propres fonctionnalit\u00e9s du syst\u00e8me d\u2019exploitation \u00bb est \u00ab l\u2019un des meilleurs moyens d\u2019\u00e9chapper \u00e0 la d\u00e9tection \u00bb.<\/p>\n<h2>Fonctionnement de ShrinkLocker<\/h2>\n<p>ShrinkLocker v\u00e9rifie la version de Windows avant de lancer son attaque. Si le syst\u00e8me est ant\u00e9rieur \u00e0 Vista, il ne chiffre pas les donn\u00e9es et s\u2019autod\u00e9truit. Pour les versions plus r\u00e9centes, il r\u00e9duit les parties du disque dur sans syst\u00e8me d\u2019exploitation, r\u00e9installe les fichiers de d\u00e9marrage et utilise BitLocker pour chiffrer les donn\u00e9es. Toutes les protections par d\u00e9faut sont d\u00e9sactiv\u00e9es et remplac\u00e9es par celles du ransomware. Une cl\u00e9 de cryptage de 64 caract\u00e8res est g\u00e9n\u00e9r\u00e9e, et le syst\u00e8me est forc\u00e9 \u00e0 s\u2019arr\u00eater, rendant la r\u00e9cup\u00e9ration des fichiers presque impossible. Les attaquants laissent une adresse mail dans les nouvelles partitions de d\u00e9marrage pour que les victimes puissent n\u00e9gocier la cl\u00e9 de d\u00e9chiffrement.<\/p>\n<h2>Une Menace en \u00e9volution<\/h2>\n<p>ShrinkLocker d\u00e9montre que les cybercriminels affinent constamment leurs tactiques. Cette menace souligne \u00e9galement que les fonctionnalit\u00e9s de Windows, comme BitLocker, peuvent \u00eatre d\u00e9tourn\u00e9es \u00e0 des fins malveillantes, n\u00e9cessitant une vigilance accrue des utilisateurs et des mesures de s\u00e9curit\u00e9 renforc\u00e9es.<\/p>\n<p>Pour se prot\u00e9ger contre des attaques comme celles de ShrinkLocker, il est essentiel de :<\/p>\n<ul>\n<li>Mettre \u00e0 jour r\u00e9guli\u00e8rement son syst\u00e8me d\u2019exploitation et ses logiciels<\/li>\n<li>Utiliser des solutions de s\u00e9curit\u00e9 robustes<\/li>\n<li>Sauvegarder fr\u00e9quemment ses donn\u00e9es sur des supports externes<\/li>\n<\/ul>\n<p>Restez vigilant et inform\u00e9 pour prot\u00e9ger efficacement vos donn\u00e9es contre les menaces de ransomware.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Nouveau Ransomware ShrinkLocker : Une menace inqui\u00e9tante pour les utilisateurs Windows Les experts de Kaspersky ont d\u00e9couvert un nouveau ransomware, nomm\u00e9 ShrinkLocker, qui cible sp\u00e9cifiquement les ordinateurs sous Windows. Ce malware exploite BitLocker, le module de chiffrement int\u00e9gr\u00e9 par Microsoft, pour passer inaper\u00e7u. BitLocker, introduit en 2007 avec Windows Vista, permet aux utilisateurs de prot\u00e9ger [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":235,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_crdt_document":"","site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[5],"tags":[36,37,13],"class_list":["post-234","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-actualites","tag-ransomware","tag-securite","tag-windows-2"],"_links":{"self":[{"href":"https:\/\/www.diskigo.com\/blog\/wp-json\/wp\/v2\/posts\/234","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.diskigo.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.diskigo.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.diskigo.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.diskigo.com\/blog\/wp-json\/wp\/v2\/comments?post=234"}],"version-history":[{"count":1,"href":"https:\/\/www.diskigo.com\/blog\/wp-json\/wp\/v2\/posts\/234\/revisions"}],"predecessor-version":[{"id":236,"href":"https:\/\/www.diskigo.com\/blog\/wp-json\/wp\/v2\/posts\/234\/revisions\/236"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.diskigo.com\/blog\/wp-json\/wp\/v2\/media\/235"}],"wp:attachment":[{"href":"https:\/\/www.diskigo.com\/blog\/wp-json\/wp\/v2\/media?parent=234"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.diskigo.com\/blog\/wp-json\/wp\/v2\/categories?post=234"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.diskigo.com\/blog\/wp-json\/wp\/v2\/tags?post=234"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}