logo

ATT&CKing ProLock Ransomware

ID: 03e31aa9-2746-5904-b317-42860c2617c5

STIX ID: report--03e31aa9-2746-5904-b317-42860c2617c5

Feed Name: Group-IB Blog

Threat Score
75/100

Date Published: 2020-05-14

Date Updated: 2026-04-27

...
...

ProLock ransomware, active since March 2020 as a successor to PwndLocker, targets enterprise organizations (financial, healthcare, government, retail) using QakBot and exposed/weak RDP for initial access. Operators use PowerShell to extract and run payloads in memory, employ credential dumping and lateral movement (PsExec, WMIC, RDP), archive and exfiltrate data with 7Zip and Rclone, then deploy ProLock enterprise-wide to encrypt files (adding .proLock/.pr0Lock/.proL0ck extensions) and demand large ransoms (examples include embedded 35 BTC demands). The report includes MITRE ATT&CK mappings, sample commands/scripts, and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.