ProLock
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
The threat actor operates under the aliases PwndLocker and ProLock and is believed to be based in Russia. It is known for deploying ransomware that was originally called PwndLocker before being rebranded as ProLock after a decryption tool released by Emsisoft reduced the effectiveness of the original variant. The group typically demands six‑figure ransom payments, with observed demands ranging from $175,000 to over $660,000 depending on the size of the victim network. Their attacks often occur on weekends when target organizations have reduced IT staffing, allowing the ransomware to spread with less immediate opposition. Before deploying the ransomware, the actors frequently attempt to exfiltrate sensitive data to use as leverage, threatening to publish or sell the information if the ransom is not paid.
In April 2020 Diebold Nixdorf suffered a ProLock ransomware infection that was confined to the corporate network, disrupting a field‑service technician automation system and affecting services for over 100 customers while ATMs, customer networks and public‑facing services remained untouched. The attackers demanded a six‑figure sum, which Diebold refused to pay, and noted that the ProLock decryption tool could corrupt large files unless a special fix—available only to paying victims—was applied. In March 2020 the city of Novi Sad was hit by PwndLocker ransomware that encrypted the municipal network, deleted Shadow Volume Copies, disabled critical Windows services and terminated security and backup processes, with files receiving extensions such as .key or .pwnd while certain system directories were excluded. The Novi Sad attackers claimed to have exfiltrated sensitive data, demanded payment in Bitcoin via a Tor portal, and threatened to release the stolen information if the ransom was not met, while also disabling backup solutions and database services to impede recovery. In February 2020 La Salle County experienced a ransomware incident that locked access to local systems; investigators noted a newly identified variant that bypassed existing defenses, but no evidence of data theft beyond encryption was found.
Following the La Salle County attack, the threat actors communicated with security researcher Lawrence Abrams, sending him an image and a list of folders that suggested they had accessed sensitive data from the victim, although no public leak or confirmation of actual exfiltration emerged. The group has indicated an intention to move toward publishing stolen data, noting that they are heading toward establishing a leak‑site similar to other ransomware gangs, though they have not yet launched their own blog. Their ransom notes consistently warn victims against using third‑party decryption tools, asserting that only the attackers possess the correct keys to restore files. The decryption tool supplied by the gang is known to corrupt large files unless a specific patch—provided only after ransom payment—is applied, a tactic observed in the Diebold Nixdorf case. Despite the threats of data leakage, victims such as Diebold Nixdorf and La Salle County have reported recovering operations without paying, relying on offline backups and incident‑response assistance from law enforcement and vendor partners.
The threat actor’s operational pattern combines weekend‑timed intrusions, service disruption, shadow‑copy deletion, and file‑extension‑based encryption to maximize impact while attempting to pressure victims through alleged data theft. Their suspected Russian origin aligns with broader trends of ransomware groups operating from that region, although no definitive attribution beyond the stated location has been provided in the source material. By leveraging the fear of data exposure and the technical limitation of their decryption utility, they seek to compel payment even when victims possess viable backup strategies. The observed shift from pure encryption to threatened data leakage reflects an evolution in their extortion model, consistent with the rebranding from PwndLocker to ProLock. Overall, the actor demonstrates a financially motivated, flexible ransomware operation that blends technical disruption with psychological pressure to extort victims.
Incidents
Attributed incidents are available to members.
3 incidents