BitLocker ransomware refers to a malicious approach where threat actors weaponize Microsoft's legitimate BitLocker full-disk encryption feature, often through custom scripts, to lock victims out of their systems or data. This method avoids the deployment of traditional ransomware executables, instead leveraging a native operating system tool, which makes detection more challenging. The primary motivation behind these attacks is financial extortion, demanding a ransom for the decryption key, though some instances have suggested a motive of sabotage. This tactic is distinct from a conventional ransomware family as it repurposes a built-in security measure rather than relying on unique malware code. One notable variant utilizing this technique is called ShrinkLocker, which involves partition resizing and specific Windows version targeting. These attacks are characterized by their ability to achieve full disk encryption, posing significant recovery challenges without the legitimate BitLock