Between June 2020 and March 2021, Lockean attacked at least seven more companies with various ransomware families: Maze, Egregor, ProLock, REvil.
ProLock
ProLock is a Windows ransomware family, previously known as PwndLocker/PwndLcker, that was rebranded as ProLock in 2019.
Profile source: Mallory opens in a new tabProLock
Family profile
ProLock is a Windows ransomware family, previously known as PwndLocker/PwndLcker, that was rebranded as ProLock in 2019. It has been described as a relatively uncommon ransomware strain that went through multiple names and iterations. ProLock encrypts files on compromised hosts using RC6 and encrypts the key with RSA-1024. It can remove Volume Shadow Copies using vssadmin.exe and can use WMIC to execute scripts on targeted hosts. Reported privilege-escalation activity includes exploitation of CVE-2019-0859. The malware can use JPG and BMP files to store its payload. ProLock has been associated with QakBot/Qbot infections as an initial access vector or delivery mechanism, and reporting states that QakBot infections have led to deployment of ProLock. France’s CERT reported that the Lockean ransomware affiliate operation used ProLock alongside Maze, Egregor, and REvil, and that TA551 collaborated with Lockean by helping affiliates drop ProLock payloads on devices infected with Qbot/QakBot. The content also notes ties or reported links involving Sekhmet, LockBit, and Maze affiliates. A notable incident cited involved Diebold Nixdorf, where investigators determined intruders installed ProLock ransomware on the company’s corporate network. At the time described in the reporting, ProLock operators had not yet launched their own public leak blog, though reporting indicated movement toward data-theft extortion. Typical ransom demands cited in the content ranged from about $175,000 to more than $660,000 depending on victim size.
Operational record
Reported operators
Threat actors
1 named in public reportingExploited software
Vulnerabilities linked to ProLock
1 CVEsMITRE ATT&CK