Emsisoft disclosed a weakness in PwndLocker ransomware that allows victims to recover encrypted files without paying, offering a free decryption path for organizations hit by the malware. The ransomware had targeted municipalities, government services, and enterprises in the United States and Europe, with reported ransom demands ranging from $175,000 to more than $660,000; named victims included LaSalle County, Illinois, which reportedly faced a 50 bitcoin demand, and the City of Novi Sad, Serbia, where more than 50 TB of data was encrypted.
PwndLocker, also tracked in some cases as KeyLocker, typically used the ransom note H0w_T0_Rec0very_Files.txt, appended extensions such as .pwnd and .key, and threatened to leak stolen data while increasing the ransom over time. Researchers said victims need a copy of the ransomware executable used in the attack to enable recovery, even though operators often delete it after deployment; potential recovery locations include %Temp%, C:\User, and %AppData%, and the file may also be recoverable through Shadow Explorer or file recovery tools. Separate reporting also noted a flaw in the attackers’ own decryptor that could fail on files larger than 64 MB, meaning some victims might not have been able to fully restore data even after paying.

TTPs, infrastructure, and targeting history in one profile.
4 events from the most recent confirmed update back to the earliest known activity.
Emsisoft, through analysis by Fabian Wosar, discovered a flaw in PwndLocker that allows victims to recover encrypted files without paying the ransom, provided they can supply the ransomware executable used in the attack.
A February 24, 2020 update associated PwndLocker with the email address help0f0ry0u@protonmail.com and the Tor URL ax3spapdymip4jpy.onion.
The campaign described in the reference continued into February 2020 after its late-2019 activity, indicating ongoing ransomware operations against organizations.
The referenced content says PwndLocker activity was concentrated from October through December 2019, targeting municipal administrations, government services, enterprises, and other organizations in the United States, Serbia, and other European countries.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.