Skip to content

ProLock

ProLock is a Windows ransomware family, previously known as PwndLocker/PwndLcker, that was rebranded as ProLock in 2019.

Profile source: Mallory opens in a new tab

ProLock

Family profile

ProLock is a Windows ransomware family, previously known as PwndLocker/PwndLcker, that was rebranded as ProLock in 2019. It has been described as a relatively uncommon ransomware strain that went through multiple names and iterations. ProLock encrypts files on compromised hosts using RC6 and encrypts the key with RSA-1024. It can remove Volume Shadow Copies using vssadmin.exe and can use WMIC to execute scripts on targeted hosts. Reported privilege-escalation activity includes exploitation of CVE-2019-0859. The malware can use JPG and BMP files to store its payload. ProLock has been associated with QakBot/Qbot infections as an initial access vector or delivery mechanism, and reporting states that QakBot infections have led to deployment of ProLock. France’s CERT reported that the Lockean ransomware affiliate operation used ProLock alongside Maze, Egregor, and REvil, and that TA551 collaborated with Lockean by helping affiliates drop ProLock payloads on devices infected with Qbot/QakBot. The content also notes ties or reported links involving Sekhmet, LockBit, and Maze affiliates. A notable incident cited involved Diebold Nixdorf, where investigators determined intruders installed ProLock ransomware on the company’s corporate network. At the time described in the reporting, ProLock operators had not yet launched their own public leak blog, though reporting indicated movement toward data-theft extortion. Typical ransom demands cited in the content ranged from about $175,000 to more than $660,000 depending on victim size.

Operational record

1
YARA rules
1
Ransom notes
1
Leak sites
0 available

Reported operators

Threat actors

1 named in public reporting
Lockean

Between June 2020 and March 2021, Lockean attacked at least seven more companies with various ransomware families: Maze, Egregor, ProLock, REvil.

Exploited software

Vulnerabilities linked to ProLock

1 CVEs

MITRE ATT&CK

ProLock in ATT&CK

7 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.