Executive Summary
ProLock is a modern Windows ransomware that leverages the QakBot distribution channel to infiltrate networks. It encrypts key files with AES-256, disables recovery mechanisms, and demands cryptocurrency ransom payments for decryption keys. The threat is most prevalent in Big Game Hunting campaigns targeting high‑value data.
Enhanced Description
ProLock is a Windows‑based ransomware strain that has operated under the Big Game Hunting (BGH) threat‑actor umbrella since at least 2020. It evolved as the successor to the PwndLocker family, which famously suffered from a decryption bug that allowed victims to recover data without paying ransom in 2019. ProLock inherits much of PwndLocker's methodology but has been refined to avoid the earlier vulnerability and increase its impact. The operation typically begins with initial compromise via the QakBot loader—a well‑known botnet used for distribution of malicious payloads. Once inside a network, QakBot delivers the ProLock executable, which scans for sensitive directories such as Documents, Desktop, Pictures, and common enterprise data stores. The malware then encrypts files using industry‑grade cryptographic primitives (AES‑256) with unique session keys, appends its own file extension (.plock), and removes original clear‑text copies. After encryption is complete, ProLock drops a ransom note that demands payment in Bitcoin or other cryptocurrencies to obtain the decryption key. Successful victims reported that the ransomware also disables Windows recovery options, patches system services to prevent rollback, and attempts to evade detection through obfuscated scripts and process injection techniques typical of QakBot’s modular architecture. Impact is severe; organizations are left without critical files until a backup or paid solution is used. The strain targets both small enterprises and larger institutions, often delivering the initial payload via spear‑phishing emails or compromised web portals that trick users into executing an infected document.
Key Capabilities
ATT&CK Techniques
Recommended Actions
Suggested Tags
Confidence Assessment
The data set contains only a high‑level description and historical context. While the classification of ProLock as a ransomware successor to PwndLocker is reliable, detailed technical behaviors (encryption algorithms beyond AES-256, communication protocols, precise initial access vectors) are not fully documented. Confidence in general capabilities is moderate; specific indicator knowledge remains incomplete.
ProLock is a ransomware strain that has been used in Big Game Hunting (BGH) operations since at least 2020, often obtaining initial access with QakBot. ProLock is the successor to PwndLocker ransomware which was found to contain a bug allowing decryption without ransom payment in 2019.(Citation: Group IB Ransomware September 2020)