Uptime Hamster: 21d 9h 19mDeploy: 3 Aug 2026 06:56Updated: 2026-07-21
Logo del actor de amenaza Proton Ransomware

Proton Ransomware

0 incidentes 0 paises 0 sectores ransomware Global Ultimo: -
Aliases: Proton Locker
Ver en IntelTracker → APTTrail →
Proton Ransomware is a financially motivated cybercriminal group that emerged in March 2023, primarily targeting Windows systems to encrypt files and demand ransom. The group has undergone several iterations and rebranding, introducing new variants such as Zola, Shinra, Ripa, Cipher, Limba, and Matrix. While initial samples utilized ECC and AES-GCM encryption, later variants, starting in September 2023, switched to ChaCha20. The group is assessed with moderate confidence to be of Iranian origin, partly due to the Zola variant's inclusion of a kill switch that checks for a Persian keyboard layout. Proton Ransomware distinguishes itself by employing a dual extortion model, encrypting victim files and threatening to leak stolen sensitive data, and has been observed using misleading ransom notes that may claim older encryption algorithms despite implementing newer ones. It should not be confused with the unrelated PrOToN/Xorist ransomware.

Aliases del actor

Proton Locker

Actores similares

bitlockerransomware · 0Mount Lockerransomware · 0Ragnar Lockerransomware · 0 Babuk-Lockerransomware · 0Loki Lockerransomware · 0Fs0ciety Locker Ransomwareransomware · 0lockbit3ransomware · 2016qilinransomware · 1933akiraransomware · 1524playransomware · 1268
Tecnicas MITRE
T1566.001, T1059.001, T1133, T1190, T1486, T1078
Tipo
ransomware
Pais origen
Global
Motivacion
-
Impacto
67
Actualizado
Fri, 19 Ju

Paises objetivo (OSINT)

AustraliaBulgariaBrazilChinaGermanyEstoniaSpainFranceUnited KingdomHong Kong

Sectores objetivo (OSINT)

Software PublishersEnterprises & HoldingAir TransportationManufacturingPublic AdministrationEducational ServicesWholesale TradeInsurancePublishing ServicesTelecommunications