prolock logo

prolock

1 incidentes 1 paises 1 sectores ransomware Ultimo: 2026-06-25
Aliases: ProLocker, PwndLocker
Ver en IntelTracker → APTTrail →
ProLock is a human-operated ransomware group that emerged in late 2019, initially operating as PwndLocker before rebranding in March 2020 after security researchers released a free decrypter for its predecessor. The group's primary motivation is financial gain, achieved by targeting large enterprises in a 'big-game hunting' approach to extract substantial ransom payments. ProLock distinguished itself by being among the first ransomware operations to consistently leverage the QakBot trojan for initial network access. A notable characteristic of the group was that their provided decryptor often corrupted files larger than 64MB, even after victims paid the ransom. The group also adopted double extortion tactics, exfiltrating data prior to encryption and threatening its public release if demands were not met.
Tecnicas MITRE
T1078, T1021, T1047, T1059, T1069

RansomLook pivots

Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.

Abrir perfil →
Data
RecentBrowseTrendingStats
Intel
GroupURLsCryptoLeaksNotesAnalysesTorrents
Info
APIGlossaryAbout
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

United States (1)

Paises objetivo (SOCRadar)

CanadaCyprusNamibiaSerbiaUnited States

Sectores atacados

Software (1)

Sectores objetivo (SOCRadar)

ConstructionManufacturingWholesale TradeRetailFinanceProfessional&Technical ServicesEnterprises & HoldingHealthCare & Social AssistancePublic AdministrationConstruction of Buildings

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com