ProLock ransomware was used in targeted intrusions against organizations after attackers gained access through QakBot, phishing campaigns, and exposed or compromised RDP services. Reporting linked ProLock to the earlier PwndLocker family and described it as the final stage of a broader compromise in which operators conducted reconnaissance, abused legitimate Windows processes, and used batch scripts, Task Scheduler, and PowerShell to deploy the encryptor across victim environments.
Once executed, ProLock disabled processes and services, deleted shadow copies, and encrypted files larger than 8,192 bytes while leaving the first 8,192 bytes intact before appending the .prolock extension and dropping ransom notes. The campaign drew additional scrutiny after the FBI warned that some victims who paid received a faulty decryptor that corrupted files instead of restoring them, underscoring both the operational risk of payment and the likelihood that data theft could accompany the encryption phase.

TTPs, infrastructure, and targeting history in one profile.
5 events from the most recent confirmed update back to the earliest known activity.
In May 2020, the FBI said ProLock operators were gaining access to victim networks through Qakbot infections, indicating that Qakbot-compromised systems could be used as entry points for ransomware deployment. The article also noted Group-IB had observed the same Qakbot-to-ProLock relationship.
In May, the FBI issued an alert saying some ProLock victims who paid the ransom received a faulty decryptor that corrupted files instead of restoring them properly. The FBI also said victims included healthcare organizations, government agencies, financial institutions, and retailers.
Sophos first encountered ProLock on a customer network in mid-March, when Intercept X CryptoGuard detected the ransomware. Sophos assessed that this early case likely involved exploitation of an RDP connection on a compromised server.
ProLock appeared in March as a reworked version of PwndLocker. The ransomware became part of a broader wave of targeted attacks during the COVID-19 period.
PwndLocker's distribution was short-lived because decryption keys could be recovered from the malware itself without paying the ransom. This weakness preceded the appearance of ProLock as its successor.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
5 references tracked. Mallory keeps watching after this page renders.
news.sophos.com
Open sourcezdnet.com
Open sourceid-ransomware.blogspot.com
Open sourcegroup-ib.com
Open sourcegroup-ib.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.