Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware ProLock

ProLock

TLP:CLEAR
Family

AI Analysis

· 17 hours ago

Executive Summary

ProLock is a modern Windows ransomware that leverages the QakBot distribution channel to infiltrate networks. It encrypts key files with AES-256, disables recovery mechanisms, and demands cryptocurrency ransom payments for decryption keys. The threat is most prevalent in Big Game Hunting campaigns targeting high‑value data.

Enhanced Description

ProLock is a Windows‑based ransomware strain that has operated under the Big Game Hunting (BGH) threat‑actor umbrella since at least 2020. It evolved as the successor to the PwndLocker family, which famously suffered from a decryption bug that allowed victims to recover data without paying ransom in 2019. ProLock inherits much of PwndLocker's methodology but has been refined to avoid the earlier vulnerability and increase its impact. The operation typically begins with initial compromise via the QakBot loader—a well‑known botnet used for distribution of malicious payloads. Once inside a network, QakBot delivers the ProLock executable, which scans for sensitive directories such as Documents, Desktop, Pictures, and common enterprise data stores. The malware then encrypts files using industry‑grade cryptographic primitives (AES‑256) with unique session keys, appends its own file extension (.plock), and removes original clear‑text copies. After encryption is complete, ProLock drops a ransom note that demands payment in Bitcoin or other cryptocurrencies to obtain the decryption key. Successful victims reported that the ransomware also disables Windows recovery options, patches system services to prevent rollback, and attempts to evade detection through obfuscated scripts and process injection techniques typical of QakBot’s modular architecture. Impact is severe; organizations are left without critical files until a backup or paid solution is used. The strain targets both small enterprises and larger institutions, often delivering the initial payload via spear‑phishing emails or compromised web portals that trick users into executing an infected document.

Key Capabilities

  • Distributes via the QakBot botnet
  • Scans for sensitive directories and files
  • Encrypts files using AES-256 and appends custom extensions
  • Deletes or disables Windows recovery options
  • Drops a ransom note with payment instructions
  • Uses obfuscated scripts and process injection to evade detection

ATT&CK Techniques

T1486
T1059
T1078
T1490

Recommended Actions

  • Block known QakBot command‑and‑control domains and IP addresses at the perimeter firewall
  • Implement host‑based threat‑intelligence solutions that detect QakBot and ProLock signatures
  • Apply timely patching of Windows and critical software to close known exploitation vectors
  • Maintain out‑of‑band, regularly updated backups for quick restoration
  • Enable file integrity monitoring to alert on abrupt file encryption events
  • Use antivirus and endpoint detection systems configured with behavioral heuristics against ransomware patterns such as .plock extensions

Suggested Tags

ransomware
Windows
ProLock
PwndLocker
QakBot
Big Game Hunting
cryptolocker
botnet
financial extortion

Confidence Assessment

The data set contains only a high‑level description and historical context. While the classification of ProLock as a ransomware successor to PwndLocker is reliable, detailed technical behaviors (encryption algorithms beyond AES-256, communication protocols, precise initial access vectors) are not fully documented. Confidence in general capabilities is moderate; specific indicator knowledge remains incomplete.

Description

ProLock is a ransomware strain that has been used in Big Game Hunting (BGH) operations since at least 2020, often obtaining initial access with QakBot. ProLock is the successor to PwndLocker ransomware which was found to contain a bug allowing decryption without ransom payment in 2019.(Citation: Group IB Ransomware September 2020)

Details

Type
Malware
Platforms
Windows
Confidence
90%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.