New GhostLock tool abuses Windows API to block file access

A security researcher has released a proof-of-concept tool named GhostLock that demonstrates how a legitimate Windows file API can be abused in attacks to block access to files stored locally or on SMB network shares.

BleepingComputer

GhostLock Exploits Windows API to Disrupt File Access

Meet GhostLock, a proof-of-concept that cleverly exploits Windows API to disrupt file access, causing operational downtime without data loss, similar to the impact of ransomware. By manipulating the CreateFileW sharing parameter, GhostLock effectively locks files, leaving other processes in the dark with a sharing violation error.

https://osintsights.com/ghostlock-exploits-windows-api-to-disrupt-file-access?utm_source=mastodon&utm_medium=social

#WindowsApi #Ghostlock #DisruptionTactics #Proofofconcept #EmergingThreats

GhostLock Exploits Windows API to Disrupt File Access

Learn how GhostLock exploits Windows API to disrupt file access and find out how to protect your systems from this new threat, read more now.

OSINTSights

Windows SMB Flaw Enables File Lockdowns Without Traditional Ransomware Traces

New Windows 'GhostLock' flaw lets attackers lock files on SMB shares. It bypasses security and leaves no traditional ransomware traces. Learn how to respond.

#WindowsSecurity, #CyberAttack, #Ransomware, #SMB, #GhostLock

https://newsletter.tf/windows-ghostlock-flaw-locks-files-no-ransomware/

Attackers can now lock files on Windows SMB shares using a new 'GhostLock' method. This exploit is harder to detect than normal ransomware because it doesn't leave typical signs like file changes.

#WindowsSecurity, #CyberAttack, #Ransomware, #SMB, #GhostLock
https://newsletter.tf/windows-ghostlock-flaw-locks-files-no-ransomware/

Windows GhostLock flaw locks files without ransomware signs

New Windows 'GhostLock' flaw lets attackers lock files on SMB shares. It bypasses security and leaves no traditional ransomware traces. Learn how to respond.

NewsletterTF