ProLock

MITRE ATT&CK: S0654 View on attack.mitre.org

Aliases: ProLock

First seen
2020-01-01 00:00:00
Malware type
ransomware
Family
Malware family
Operating systems
windows
Related IoCs
1 (1 malicious)
Last IoC activity
2026-04-20 02:55:23
Profile updated
2026-07-07 12:58:41

Targeted industries: financial-services healthcare-and-pharmaceutical government-and-public-sector retail-and-hospitality

Targeted regions: country_code:us country_code:de

Context

ProLock is a ransomware strain that has been used in Big Game Hunting (BGH) operations since at least 2020, often obtaining initial access with QakBot. ProLock is the successor to PwndLocker ransomware which was found to contain a bug allowing decryption without ransom payment in 2019.

Recent IoC activity

1 malicious indicator in Maltiverse are attributed to ProLock (S0654). The 1 most recently updated:

TypeIndicatorUpdatedSources
file sample Evidence.7z 2026-04-20 1

Detection coverage

  • 128 Sigma rules

Malware & tools used

  • File Deletion (attack-pattern)
  • Data Encrypted for Impact (attack-pattern)
  • Windows Management Instrumentation (attack-pattern)
  • BITS Jobs (attack-pattern)
  • Steganography (attack-pattern)
  • Exploitation for Privilege Escalation (attack-pattern)
  • Inhibit System Recovery (attack-pattern)

Related threat objects

  • Qbot (infrastructure)

Reports & references

  • CrowdStrike — Report2021Gtr (report)
  • cisoclub.ru — Otchet Kompanii Group Ib Ransomware Uncovered 2020 2021 (report)
  • docs.google.com — 1Mi8Z2Tbhmqq5X8Wf Ozv3Dvjz5Sjos 3 (report)
  • web.archive.org — Otchet Kompanii Group Ib Ransomware Uncovered 2020 2021 (report)
  • cert.ssi.gouv.fr — Certfr 2021 Cti 009 (report)
  • cert.ssi.gouv.fr — Certfr 2021 Cti 009 (report)
  • cronup.com — De Ataque Con Malware A Incidente De Ransomware (report)
  • cyborgsecurity.com — Hunting Ransomware Inhibiting System Backup Or Recovery (report)
  • pwc.co.uk — What Is Behind Ransomware Attacks Increase (report)
  • medium.com — Operation Synctrek E5013Df8D167 (report)
  • zdnet.com — The Malware That Usually Installs Ransomware And You Need To Remove Right Away (report)
  • id-ransomware.blogspot.com — Pwndlocker Ransomware (report)
  • news.sophos.com — Prolock Ransomware Gives You The First 8 Kilobytes Of Decryption For Free (report)
  • norfolkinfosec.com — Tinypos And Prolocker An Odd Relationship (report)
  • raw.githubusercontent.com — When%20Ransomware%20Hits%20An%20Atm%20Giant%20 %20The%20Diebold%20Nixdorf%20Case%20Dissected%20 %20Group Ib%20Cybercrimecon2020 (report)
  • soolidsnake.github.io — Prolock Ransomware (report)
  • bleepingcomputer.com — New Pwndlocker Ransomware Targeting Us Cities Enterprises (report)
  • bleepingcomputer.com — Pwndlocker Ransomware Gets Pwned Decryption Now Available (report)
  • cert-pa.it — Pwndlocker Si Rinnova In Prolock Ransomware (report)
  • group-ib.com — Prolock (report)
  • group-ib.com — Prolock Evolution (report)
  • hornetsecurity.com — Qakbot Malspam Leading To Prolock (report)
  • hornetsecurity.com — Qakbot Reducing Its On Disk Artifacts (report)
  • intrinsec.com — Egregor Prolock (report)
  • it-klinika.rs — Paznja Novi Opasni Ransomware Pwndlocker I U Srbiji (report)

External references