Skip to content

Ransomware

PwndLocker

aka ProLock

PwndLocker is a ransomware that was observed in late 2019 and is reported to have been used to target businesses and local governments/cities.

PwndLocker, also known as ProLock, is a Windows ransomware.

Background

PwndLocker is a ransomware first seen in late 2019 and reportedly used against businesses as well as local governments and cities. One source puts its ransom demands between $175k USD and $650k USD, scaled to the size of the targeted network. The malware tries to stop a number of Windows services so their data can be encrypted, and it also goes after various processes such as web browsers and software tied to security, backups, and databases. It wipes shadow copies, and only after preparing the system in this manner does it begin encrypting files. Executables and files that the operating system likely needs to keep running are left untouched, and the ransomware also skips a large set of folders mostly tied to Microsoft Windows system files. Since March 2020, encrypted files have appeared with the appended extensions .key and .pwnd. Ransom notes are written into folders containing encrypted files and onto the user's desktop.


Source: Malpedia (Fraunhofer FKIE).