PwndLocker is a targeted ransomware family that emerged in late 2019 and was used against businesses, municipal administrations, government services, and other organizations. It encrypts victim data and demands high-value ransoms, with reported campaigns focusing on enterprise and public-sector networks in multiple countries. The malware has been associated with double-extortion behavior, with operators claiming to steal sensitive data before encryption and threatening public release if victims refuse to pay.
On compromised Windows environments, PwndLocker attempts to maximize encryption impact by terminating a broad set of security, backup, database, mail, and server-related processes and services, and by deleting shadow copies to hinder recovery. It has been observed dropping ransom notes throughout affected systems and using victim-specific encrypted-file extensions. Reporting also indicates propagation or staging through removable media in some cases.
PwndLocker has been linked to multiple initial access vectors, including exposed or insecure RDP access, phishing and malicious attachments, deceptive downloads, fake updates, malvertising, exploit-driven delivery, botnet-assisted distribution, and trojanized installers. The operators reportedly perform victim-environment assessment before launching encryption, consistent with targeted intrusion activity rather than indiscriminate mass deployment.
The family is notable for weaknesses in its implementation. Security researchers identified a flaw that enabled decryption in some cases, and reporting also noted that the original decryptor used by the operators could fail on larger files, making ransom payment unreliable. PwndLocker is also widely described as the predecessor of ProLock, which appeared as a successor or reworked follow-on family after PwndLocker’s initial activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Earlier ransomware strain and predecessor to ProLock; its distribution was short-lived because decryption keys could be recovered from the malware itself.
Ransomware that encrypts victims' files and demands large ransoms from organizations and municipalities; the article states Emsisoft found a weakness that enables decryption in some cases.
Ransomware family active since late 2019 that targets business and local government networks, attempts to stop services and kill processes associated with backups, databases, and security tools, deletes Shadow Volume Copies to hinder recovery, encrypts files (observed extensions include .key and .pwnd), and drops ransom notes (H0w_T0_Rec0very_Files.txt) directing victims to email/Tor payment portals. Operators also claim data theft prior to encryption to increase extortion pressure.
Ransomware that encrypts files across victim networks using AES, appends extensions such as .pwnd and .key, drops the ransom note H0w_T0_Rec0very_Files.txt, deletes shadow copies, kills security/backup/database processes, may spread via removable media, and extorts victims with both file encryption and stolen-data leak threats.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.