Ransomware Group: prolock

Fecha
25 Jun 2026
Actor
prolock
Tipo
Threat-actor
Pais
United States
Sector
Software
Confianza
high
50
Prioridad analitica
Baja

Basado en actor, pais, IOCs, TTPs, filtracion y calidad de contexto.

0IOCs
0TTPs
prolockActor
United StatesPais
Executive Summary
Perfil del grupo segun ransomware.anggipradana.com.

Key Points

  • Ransomware Dashboard

Grupo Ransomware: prolock

Perfil del grupo segun ransomware.anggipradana.com.

CampoValor
Alias
Pais
Estado

Descripcion

PwndLocker is a ransomware that was observed in late 2019 and is reported to have been used to target businesses and local governments/cities. According to one source, ransom amounts demanded as part of PwndLocker activity range from $175k USD to $650k USD depending on the size of the network. PwndLocker attempts to disable a variety of Windows services so that their data can be encrypted. Various processes will also be targeted, such as web browsers and software related to security, backups, and databases. Shadow copies are cleared by the ransomware, and encryption of files occurs once the system has been prepared in this way. Executable files and those that are likely to be important for the system to continue to function appear to be skipped by the ransomware, and a large number of folders mostly related to Microsoft Windows system files are also ignored. As of March 2020, encrypted files have been observed with the added extensions of .key and .pwnd. Ransom notes are dropped in folders where encrypted files are found and also on the user's desktop.

Referencias

Diamond Model

Adversary
prolock
Ver perfil →
Victim
Ransomware Group: prolock
United States
Capability
Threat-actor
Infrastructure
Sin infraestructura confirmada

Relations

Mapa de nodos relacionados por IOCs compartidos, actor, enlaces IntelTracker/OSINT, campanas y victimas observadas. Haz click en un nodo para abrir el post, filtro o fuente.

1 enlaces

Referencias y enlaces

→ Perfil del actor prolock en el blog → Ver prolock en IntelTracker → URL IntelTracker: ransomware.anggipradana.com → Fuente OSINT: ransomware.anggipradana.com → Buscar prolock en APTTrail → Repositorio APTTrail → Mas incidentes en United States → Buscar en Google News → Analizar en VirusTotal → Feed RSS del blog
← Volver al panel de inteligencia

Incidentes recientes